
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59084 is an Insufficient Technical Documentation vulnerability (CWE-1059) in Apache Tomcat's EncryptInterceptor component, where the security requirements for securely configuring the EncryptInterceptor were not clearly documented, potentially leading to insecure deployments. Disclosed on July 14, 2026, it affects Apache Tomcat versions 11.0.0-M1 through 11.0.23, 10.1.0-M1 through 10.1.56, 9.0.13 through 9.0.119, 8.5.38 through 8.5.100, and 7.0.100 through 7.0.109; end-of-life versions may also be affected. It carries a CVSS v3.1 base score of 9.1 (Critical), assigned by CISA-ADP (Apache Advisory, GitHub Advisory, Openwall OSS-Sec).
The root cause is classified as CWE-1059 (Insufficient Technical Documentation): the Apache Tomcat documentation failed to clearly specify the requirements needed to securely configure the EncryptInterceptor, a component used to encrypt cluster communication between Tomcat nodes. As a result, administrators could deploy the EncryptInterceptor with weak or insecure settings — such as inadequate encryption algorithms or poor key management — without being aware of the security implications. An unauthenticated network attacker with access to Tomcat cluster communication channels could exploit a misconfigured EncryptInterceptor to intercept and read encrypted cluster traffic or modify data in transit. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity, making it automatable (Apache Advisory, Openwall OSS-Sec).
Successful exploitation of a misconfigured EncryptInterceptor can result in high confidentiality and high integrity impact, allowing an unauthenticated attacker to intercept and read sensitive cluster communication data, as well as potentially modify encrypted data in transit between Tomcat cluster nodes. Availability is not directly impacted. The scope is limited to the affected Tomcat cluster communication channel, but exposure of session data, application state, or credentials transmitted between nodes could enable further lateral movement within the infrastructure (GitHub Advisory, Feedly).
Apache has released patched versions addressing this issue: upgrade to 11.0.24, 10.1.57, or 9.0.120 (or later) depending on your current branch. Note that Tomcat 8.5.x and 7.0.x are end-of-life and do not have official patched releases; users on those branches should migrate to a supported version. As a configuration-based mitigation, administrators should review and harden their EncryptInterceptor settings — using strong encryption algorithms, proper key management, and restricting network access to Tomcat cluster communication ports — in accordance with the updated Apache Tomcat documentation (Apache Advisory, Openwall OSS-Sec).
The vulnerability was reported by a researcher credited as "NDIx" and disclosed by Apache Tomcat committer Mark Thomas via the oss-security mailing list on July 14, 2026, with an official severity rating of "low" from Apache despite the high CVSS score assigned by CISA-ADP (Openwall OSS-Sec). The discrepancy between Apache's "low" severity label and the CVSS 9.1 Critical score generated some community discussion, as the underlying issue is a documentation gap rather than a direct code flaw. The vulnerability was included in The Hacker News' weekly security recap and covered by several security blogs and aggregators (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."