CVE-2026-34486
Apache Software Foundation Apache Tomcat, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
- CVSS
- 7.5
- EPSS
- 42.6% 98.6% percentile
- CISA KEV
- Listed
- Published
- 2026.04.10