Skip to content
CVSS 9.1 · CRITICAL

CVE-2026-65182Security Constraint Bypass in Apache Tomcat

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.

View on NVD

Analysis

Apache Tomcat versions across all major branches (7.0 through 11.0) are vulnerable to a security constraint bypass. Attackers can access protected URL paths if the server configuration orders constraints in a specific way, potentially exposing sensitive endpoints or administrative interfaces.

Relevant roles

BackendJavaCloudDockerLinuxciberseguridad

Severity

Score: 9.1(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: NONE
Weakness (CWE): CWE-284CWE-863

EPSS

Probability of exploitation (next 30 days): 0.0023 (0.2%)
Percentile: 13.1%
EPSS: 2026-08-26

Technical description

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.

Published: 8/25/2026, 10:17:04 PM
Last modified: 8/26/2026, 4:45:12 PM

References

HomeEventsBlogResourcesCoursesTeam