GHSA-gcx9-497g-6cp6CriticalCVSS 9.1

Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability

Published
August 26, 2026
Last Modified
September 2, 2026

🔗 CVE IDs covered (1)

📋 Description

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.

Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.

🎯 Affected products15

  • maven/org.apache.tomcat:tomcat:>= 11.0.0-M1, < 11.0.25
  • maven/org.apache.tomcat:tomcat:>= 10.1.0-M1, < 10.1.58
  • maven/org.apache.tomcat:tomcat:>= 9.0.0-M1, < 9.0.121
  • maven/org.apache.tomcat:tomcat:>= 8.5.0, <= 8.5.100
  • maven/org.apache.tomcat:tomcat:>= 7.0.0, <= 7.0.109
  • maven/org.apache.tomcat:tomcat-catalina:>= 11.0.0-M1, < 11.0.25
  • maven/org.apache.tomcat:tomcat-catalina:>= 10.1.0-M1, < 10.1.58
  • maven/org.apache.tomcat:tomcat-catalina:>= 9.0.0-M1, < 9.0.121
  • maven/org.apache.tomcat:tomcat-catalina:>= 8.5.0, <= 8.5.100
  • maven/org.apache.tomcat:tomcat-catalina:>= 7.0.0, <= 7.0.109
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 11.0.0-M1, < 11.0.25
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 10.1.0-M1, < 10.1.58
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 9.0.0-M1, < 9.0.121
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 8.5.0, <= 8.5.100
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 7.0.0, <= 7.0.109

🔗 References (10)