🚨SEVERITY: HIGH — CVSS 7.5Security Advisory

TL;DR 📌

  • Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
  • Highest CVSS: 7.5 (High).
  • Listed in CISA KEV (2026-08-04) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-34486.

What it is

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.