FR
live
High CVSS 7.3

CVE-2026-55957

Apache Tomcat

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.

What this means

Exposure
Exploitable remotely over the network, without authentication and with no action from the victim.
Impact
An attacker can read some data, alter some data and degrade the service.
Likelihood
Its EPSS score puts short-term exploitation in a middle band: neither negligible nor imminent.

What to doFold into the next patch cycle. Start with the instances exposed to the internet.

Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.

Published
29 June 2026
CVSS
7.3 (v3.1) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS
2.98% probability of exploitation within 30 days · above 86% of all CVEs
Weakness
CWE-304
Sources
nvd
References

Type at least two characters.

navigate open esc dismiss