CVE-2026-65182
CVE-2026-65182 updated by NVD
Summary
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| Maven | org.apache.tomcat.embed:tomcat-embed-core | — | 11.0.25, 10.1.58, 9.0.121 |
| Maven | org.apache.tomcat:tomcat | — | 11.0.25, 10.1.58, 9.0.121 |
| Maven | org.apache.tomcat:tomcat-catalina | — | 11.0.25, 10.1.58, 9.0.121 |
Remediation: Upgrade to 11.0.25 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.
Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.
EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.