CVE-2026-75973

LOWCVSS 7.3 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple web application used that provider, the realm for the first web application to authenticate a request would be used for all web applications. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M4 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60, 9.0.122, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-23: 209-23
Referenced assets2 URLs
Full discourse2 posts
  • Kazuki Omo@omokazuki

    Tomcatの脆弱性(Critical: CVE-2026-76183, CVE-2026-86248, CVE-2026-86350, High: CVE-2026-75973, CVE-2026-77762, CVE-2026-77791, CVE-2026-78383, CVE-2026-78437, CVE-2026-79677, CVE-2026-87022, Medium: CVE-2026-73581, Low: CVE-2026-77756) https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260924/

    00012124
    372 followersView on X
  • CVE@CVEnew

    CVE-2026-75973 Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple … https://www.cve.org/CVERecord?id=CVE-2026-75973

    000011.2K
    58.1K followersView on X

Explore more