CVE-2026-55956Patch(apache / tomcat)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache tomcat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 4 mentions (2026-07-01); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
tomcat

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-06-30: 1Mentions · 2026-07-01: 4Mentions · 2026-07-05: 1Mentions · 2026-07-08: 1Patch / Workaround · 2026-07-01: 3Patch / Workaround · 2026-07-05: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-01: 2Technical Details · 2026-07-05: 1Technical Details · 2026-07-08: 106-3007-0107-0507-08
Signal classification2 categories
Patch
457.1%
Disclosure
342.9%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-301
Disclosure1
2026-07-014
Disclosure2Patch2
2026-07-051
Patch1
2026-07-081
Patch1
Full discourse7 posts
  • elhacker.NET@elhackernet
    Disclosure

    Múltiples vulnerabilidades de Apache Tomcat permiten saltar la autenticación La Apache Software Foundation ha revelado dos vulnerabilidades en Apache Tomcat (CVE-2026-55957 y CVE-2026-55956) https://blog.elhacker.net/2026/07/multiples-vulnerabilidades-de-apache.html

    Post summary

    The post announces that Apache has identified two new CVEs in Tomcat, with no additional technical, exploit, or remediation details.

    011039103.8K
    141.7K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Apache Tomcat の脆弱性 CVE-2026-55957/55956 が FIX:認証バイパスの恐れ https://iototsecnews.jp/2026/07/01/multiple-apache-tomcat-vulnerabilities-allow-attackers-to-bypass-authentication/ Webアプリケーションの安全な運用を支える基盤ソフト Apache Tomcat において、本来制限されているはずの領域へ向けた外部からの侵入を許してしまう、2 件の脆弱性CVE-2026-55957/CVE-2026-55956 が公表されました。この問題の背景には、通信の種類ごとにアクセスの可否を細かく判定する内部ロジックの不備により、設定された拒否ルールが一部無視されてしまう仕組み上の不具合があります。この脆弱性を放置すると、認証の回避や重要データの窃取などが生じる恐れがあります。対応策として、開発元が配布している安全な最新バージョンへの更新を速やかに実施してください。その上で、設定ファイルのアクセス制御ルールを改めて見直すことが大切です。 #Apache #CVE202655956 #CVE202655957 #Tomcat #Vulnerability

    Post summary

    The article announces the discovery of two CVE-2026-55957/55956 vulnerabilities in Apache Tomcat that enable authentication bypass, urges users to update to the latest vendor release, and explains the technical cause of the flaw.

    01000157
    500 followersView on X
  • Aikido Community Japan@AikidoCommJP
    Patch

    Tomcat の CVE で一番気になったのは、認証バイパスそのものより「まだそこに Tomcat 8.5 / 7.0 がいる」という現実だった。 CVE-2026-55957 は、JNDIRealm + GSSAPI authenticated bind という条件が必要で、発動条件は狭い。Tomcat を使っているだけで全員が慌てる話ではない。まず見るべきは、該当構成があるかどうか。 ただし、同時公開の CVE-2026-55956 は別。default servlet の制約バイパスで、影響範囲はこちらの方が広い。GSSAPI とは関係ないので、日本の現場で普通に踏む可能性があるのは、むしろこっちかもしれない。 見る順番はこう。 まず、JNDIRealm + GSSAPI の旧構成が残っていないか。単体 Tomcat だけでなく、Spring Boot 組み込みの tomcat-embed-core も見る。 次に、CVE-2026-55956 の影響範囲を確認する。 そしてログを見るなら、単なるログイン成功ではなく、 いつ どこから どの認証方式で どのロールになり その後何をしたか を見る。 いったん認証が通ってしまえば、その後は「正規の管理者操作」に見える。ここが厄介。 で、ここからが本題。 Tomcat 9 / 10 / 11 系なら、基本は修正版へ上げる話になる。でも 8.5 / 7.0 は EOL。該当した場合、「パッチを当てれば済む」ではなく、実質的には移行案件になる。 ここで現場は止まる。 古いから上げろ。 それは正しい。 でも正しいだけでは動かない。 その上に10年前の業務アプリが載っている。担当者はいない。検証環境もない。JDK を上げると別のものが壊れる。認証連携も古い。移行はセキュリティ対応ではなく、小さな再開発案件になる。 だから残る。 そして、残ったものが次の攻撃面になる。 ここで Aikido が買収した Root の意味が出てくる。 Root / Aikido Libraries / Aikido Images が狙っているのは、「見つける」と「直す」の間に空いた溝だ。 脆弱性を見つける側は、SCA、SAST、SBOM、AIでどんどん速くなった。でも直す側は、まだ人間の手作業に残っている。 影響を調べる。 上げられるバージョンを探す。 互換性を見る。 壊れないか試す。 本番反映を調整する。 攻撃者は、この「見つかったが、まだ直っていない」時間に住んでいる。 Root の発想は、いま動いているまさにそのバージョンに、破壊的変更を避けた修正を差し込むこと。アップグレードでも移行でもなく、壊れにくい差し替えに近い。 もちろん、これは EOL を放置していいという話ではない。古いものは、上げられるなら上げるべき。 ただ、日本企業の基幹周辺には「古いが止められない」「上げたいが検証環境がない」「担当者がもういない」システムが普通にある。 EOL の本当の怖さは、脆弱性そのものより、修正判断が毎回プロジェクト化して止まることにある。 今回の Tomcat CVE は、現時点で悪用が広がっている話ではない。CVE-2026-55957 の条件も狭い。過度に煽る必要はない。 でも、放置してよい話でもない。 該当構成を切り分ける。 CVE-2026-55956 も見る。 ブラウザ経路や管理画面との複合技を考える。 ログで認証方式・権限・操作を見る。 そして EOL が残っているなら、移行だけでなく、壊さず塞ぐ現実解も考える。 古い Tomcat が動いていた。 それは一台の古いサーバの話ではない。 「見つける」ことは速くなったのに、「直す」ことだけが遅いまま残っている。 今回の CVE は、その溝をもう一度見せている。 #Aikido #Tomcat #脆弱性管理 #サプライチェーンセキュリティ #DevSecOps #OSS

    Post summary

    The post discusses technical details of Tomcat CVEs and emphasizes the need to patch or upgrade systems, especially for EOL versions, but does not assert active exploitation or provide exploit code.

    00001353
    210 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Authorization and Authentication Vulnerability in #Apache Tomcat. CVE-2026-55956 CVSS: 6.5 and CVE-2026-55957 CVSS: 7.3 This can lead to unauthorized access. Read our advisory https://ccb.belgium.be/advisories/warning-authorization-and-authentication-vulnerabilities-apache-tomcat-patch-immediately and #Patch #Patch #Patch

    Post summary

    The post warns of authorization/authentication flaws in Apache Tomcat (CVE‑2026‑55956/59) and directs users to an advisory urging immediate patching.

    01000365
    7.2K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    Apache Tomcatの脆弱性(Important: CVE-2026-55957, Moderate: CVE-2026-55956, Low: CVE-2026-55955, CVE-2026-55276, CVE-2026-53434, CVE-2026-53404, CVE-2026-50229) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #tomcat #mod_jk #apache https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260630/

    Post summary

    The post announces a set of new Apache Tomcat vulnerabilities, listing their CVE IDs and severity levels, without providing exploitation details, patches, or technical specifics.

    00010149
    369 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Two Apache Tomcat flaws (CVE-2026-55957 & CVE-2026-55956) let attackers bypass authentication by exploiting broken HTTP method-level security constraints on the default servlet-access assumed "protected" wasn't. 🔧 No workarounds exist, patch now. Upgrade to Tomcat 11.0.5/10.1.37/9.0.101+ (or 11.0.23/10.1.56/9.0.119+ for the second flaw) and audit web.xml constraints afterwards.

    Post summary

    The post announces two Apache Tomcat authentication bypass vulnerabilities (CVE‑2026‑55957 & CVE‑2026‑55956) and emphasizes the need to patch by upgrading to the latest Tomcat releases, noting no workarounds are available.

    0000051
    22 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🚨 Apache Tomcat güvenlik açığı Apache Tomcat için açıklanan CVE-2026-55957 ve CVE-2026-55956 açıkları, bazı yapılandırmalarda güvenlik kontrollerinin aşılmasına neden olabiliyor. Tomcat sürümünüzü güncelleyin ve erişim kurallarınızı kontrol edin.

    Post summary

    The message announces the disclosure of CVE-2026-55957 and CVE-2026-55956 in Apache Tomcat, noting that they can bypass security controls in certain configurations, and urges users to update their Tomcat installation and review access rules.

    00000194
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---

Explore more