{
  "threat_severity" : "Important",
  "public_date" : "2026-04-09T19:35:35Z",
  "bugzilla" : {
    "description" : "Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass",
    "id" : "2457027",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2457027"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-807",
  "details" : [ "Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.\nThis issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.\nUsers are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.", "A flaw was found in Apache Tomcat. This vulnerability, categorized as Missing Encryption of Sensitive Data, arises from a bypass in the EncryptInterceptor, a component designed to ensure data encryption. This bypass, introduced as a fix for CVE-2026-29146, allows sensitive data to remain unencrypted, potentially leading to information disclosure." ],
  "statement" : "This is an Important flaw in Apache Tomcat where a bypass in the EncryptInterceptor allows sensitive data to remain unencrypted. This could lead to information disclosure in Red Hat Enterprise Linux and Red Hat JBoss Web Server environments utilizing affected versions of Apache Tomcat.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36788",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "tomcat-1:10.1.49-3.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36790",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "tomcat9-1:9.0.117-2.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36787",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "tomcat-1:10.1.36-2.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36789",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "tomcat9-1:9.0.87-6.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
    "release_date" : "2026-07-13T00:00:00Z",
    "advisory" : "RHSA-2026:38505",
    "cpe" : "cpe:/o:redhat:rhel_els:7",
    "package" : "tomcat-0:7.0.76-18.el7_9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-09T00:00:00Z",
    "advisory" : "RHSA-2026:37137",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "tomcat-1:9.0.87-2.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-07-09T00:00:00Z",
    "advisory" : "RHSA-2026:37136",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "tomcat-1:9.0.87-2.el8_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-07-09T00:00:00Z",
    "advisory" : "RHSA-2026:37136",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "tomcat-1:9.0.87-2.el8_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36879",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "tomcat-1:9.0.117-2.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36878",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "tomcat-1:9.0.87-2.el9_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36876",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "tomcat-1:9.0.87-2.el9_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36877",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "tomcat-1:9.0.87-4.el9_6"
  }, {
    "product_name" : "Red Hat JBoss Web Server 7.0.0",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39189",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
    "package" : "tomcat"
  }, {
    "product_name" : "Red Hat JBoss Web Server 7.0 on RHEL 10",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39188",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
    "package" : "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el10jws"
  }, {
    "product_name" : "Red Hat JBoss Web Server 7.0 on RHEL 8",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39188",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
    "package" : "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el8jws"
  }, {
    "product_name" : "Red Hat JBoss Web Server 7.0 on RHEL 9",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39188",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
    "package" : "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el9jws"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "tomcat6",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Will not fix",
    "package_name" : "pki-deps:10.6/pki-servlet-engine",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Will not fix",
    "package_name" : "pki-servlet-engine",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat JBoss Web Server 5",
    "fix_state" : "Will not fix",
    "package_name" : "tomcat",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:5"
  }, {
    "product_name" : "Red Hat JBoss Web Server 6",
    "fix_state" : "Affected",
    "package_name" : "tomcat",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:6"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-34486\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-34486\nhttps://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly" ],
  "name" : "CVE-2026-34486",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}