Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66422

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 2.7
EPSS Низкий

Описание

Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

A flaw was found in Apache Tomcat. This improper authorization vulnerability occurs because security-role-ref definitions are incorrectly used as role aliases within the Realm, in addition to their correct usage with Request.isUserInRole(). This misconfiguration allows for a bypass of declarative role constraints, which could lead to unauthorized access to resources that should be restricted based on user roles.

Отчет

This vulnerability is rated as Low impact. It requires high privileges to exploit and only affects the confidentiality of information by allowing a bypass of declarative role constraints. In Red Hat deployments, where Apache Tomcat instances are typically configured with strict access controls, this flaw primarily impacts already highly privileged users, limiting its overall risk.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tomcatUnder investigation
Red Hat Enterprise Linux 10tomcat9Under investigation
Red Hat Enterprise Linux 6tomcat6Under investigation
Red Hat Enterprise Linux 7tomcatUnder investigation
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineUnder investigation
Red Hat Enterprise Linux 8tomcatUnder investigation
Red Hat Enterprise Linux 9tomcatUnder investigation
Red Hat JBoss Web Server 5tomcatOut of support scope
Red Hat JBoss Web Server 6tomcatAffected
Red Hat JBoss Web Server 7tomcatAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-386
https://bugzilla.redhat.com/show_bug.cgi?id=2524156tomcat: Apache Tomcat: Improper Authorization allows bypass of declarative role constraints

EPSS

Процентиль: 46%
0.00574
Низкий

2.7 Low

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
30 дней назад

Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 8.1
nvd
30 дней назад

Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 8.1
debian
30 дней назад

Improper Authorization vulnerability in Apache Tomcat cause by securit ...

CVSS3: 8.1
redos
3 дня назад

Уязвимость tomcat11

CVSS3: 8.1
redos
3 дня назад

Уязвимость tomcat10

EPSS

Процентиль: 46%
0.00574
Низкий

2.7 Low

CVSS3