Skip to content
COOEY

EXPOSURES › CVE-2026-34486

CVE-2026-34486

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-08-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-34486 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Apache Tomcat missing encryption of sensitive data allows bypass of EncryptInterceptor.

Apache Tomcat contains a vulnerability that allows sensitive data to be bypassed, enabling potential data exposure. This is a critical issue for organizations using Tomcat, as it can lead to data breaches if not addressed promptly. Immediate action is required to patch and secure the system.

Shame score — The vulnerability allows sensitive data to be bypassed, posing a significant risk to data integrity and confidentiality.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.