CVE-2026-59084
Apache Tomcat vulnerability analysis and mitigation

Overview

CVE-2026-59084 is an Insufficient Technical Documentation vulnerability (CWE-1059) in Apache Tomcat's EncryptInterceptor component, where the security requirements for securely configuring the EncryptInterceptor were not clearly documented, potentially leading to insecure deployments. Disclosed on July 14, 2026, it affects Apache Tomcat versions 11.0.0-M1 through 11.0.23, 10.1.0-M1 through 10.1.56, 9.0.13 through 9.0.119, 8.5.38 through 8.5.100, and 7.0.100 through 7.0.109; end-of-life versions may also be affected. It carries a CVSS v3.1 base score of 9.1 (Critical), assigned by CISA-ADP (Apache Advisory, GitHub Advisory, Openwall OSS-Sec).

Technical details

The root cause is classified as CWE-1059 (Insufficient Technical Documentation): the Apache Tomcat documentation failed to clearly specify the requirements needed to securely configure the EncryptInterceptor, a component used to encrypt cluster communication between Tomcat nodes. As a result, administrators could deploy the EncryptInterceptor with weak or insecure settings — such as inadequate encryption algorithms or poor key management — without being aware of the security implications. An unauthenticated network attacker with access to Tomcat cluster communication channels could exploit a misconfigured EncryptInterceptor to intercept and read encrypted cluster traffic or modify data in transit. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity, making it automatable (Apache Advisory, Openwall OSS-Sec).

Impact

Successful exploitation of a misconfigured EncryptInterceptor can result in high confidentiality and high integrity impact, allowing an unauthenticated attacker to intercept and read sensitive cluster communication data, as well as potentially modify encrypted data in transit between Tomcat cluster nodes. Availability is not directly impacted. The scope is limited to the affected Tomcat cluster communication channel, but exposure of session data, application state, or credentials transmitted between nodes could enable further lateral movement within the infrastructure (GitHub Advisory, Feedly).

Mitigation and workarounds

Apache has released patched versions addressing this issue: upgrade to 11.0.24, 10.1.57, or 9.0.120 (or later) depending on your current branch. Note that Tomcat 8.5.x and 7.0.x are end-of-life and do not have official patched releases; users on those branches should migrate to a supported version. As a configuration-based mitigation, administrators should review and harden their EncryptInterceptor settings — using strong encryption algorithms, proper key management, and restricting network access to Tomcat cluster communication ports — in accordance with the updated Apache Tomcat documentation (Apache Advisory, Openwall OSS-Sec).

Community reactions

The vulnerability was reported by a researcher credited as "NDIx" and disclosed by Apache Tomcat committer Mark Thomas via the oss-security mailing list on July 14, 2026, with an official severity rating of "low" from Apache despite the high CVSS score assigned by CISA-ADP (Openwall OSS-Sec). The discrepancy between Apache's "low" severity label and the CVSS 9.1 Critical score generated some community discussion, as the underlying issue is a documentation gap rather than a direct code flaw. The vulnerability was included in The Hacker News' weekly security recap and covered by several security blogs and aggregators (Feedly).

Additional resources


SourceThis report was generated using AI

Related Apache Tomcat vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59084CRITICAL9.1
  • Apache Tomcat logoApache Tomcat
  • tomcat-servlet-4.0-api
NoYesJul 14, 2026
CVE-2026-59083CRITICAL9.1
  • Apache Tomcat logoApache Tomcat
  • tomcat
NoYesJul 14, 2026
CVE-2026-55957HIGH7.3
  • Apache Tomcat logoApache Tomcat
  • tomcat9-docs-webapp
NoYesJun 29, 2026
CVE-2026-55956MEDIUM6.5
  • Apache Tomcat logoApache Tomcat
  • tomcat-el-3_0-api
NoYesJun 29, 2026
CVE-2026-55955MEDIUM6.5
  • Apache Tomcat logoApache Tomcat
  • tomcat9
NoYesJun 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management