EXPOSURES › CVE-2026-34486
CVE-2026-34486
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Tomcat missing encryption of sensitive data allows bypass of EncryptInterceptor.
Apache Tomcat contains a vulnerability that allows sensitive data to be bypassed, enabling potential data exposure. This is a critical issue for organizations using Tomcat, as it can lead to data breaches if not addressed promptly. Immediate action is required to patch and secure the system.
Shame score — The vulnerability allows sensitive data to be bypassed, posing a significant risk to data integrity and confidentiality.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.