🚨SEVERITY: HIGH — CVSS 7.5Security Advisory
TL;DR 📌
- Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
- Highest CVSS: 7.5 (High).
- Listed in CISA KEV (2026-08-04) — this is being exploited in the wild.
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2026-34486.
What it is
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.