CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2026-08-04. EPSS: 6.6% chance of exploitation in the next 30 days.

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Affected products

  • Apache Tomcat: version 9.0.116 only; version 10.1.53 only; version 11.0.20 only
  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Red Hat Enterprise Linux Els: version 7.0 only
  • Red Hat Enterprise Linux Eus: version 10.0 only
  • Red Hat Enterprise Linux Tus: version 8.8 only
  • Red Hat Enterprise Linux Update Services For SAP Solutions: version 8.8 only; version 9.2 only; version 9.4 only; version 9.6 only
  • Red Hat JBoss Web Server: version 7.0.0 only

Published 2026-04-09. Last modified 2026-09-21.