Apache Tomcat's security team has released security updates addressing multiple vulnerabilities, including (CVE-2026-65182), a security constraint bypass vulnerability in Apache Tomcat's request-authorization processing. If exploited, this vulnerability could allow an attacker to bypass authentication and security controls on affected systems.
Affected Systems:
Apache Tomcat versions from 9.0.0.M1 to 9.0.120
Apache Tomcat versions from 10.1.0-M1 to 10.1.57
Apache Tomcat versions from 11.0.0-M1 to 11.0.24
Security Risks
Successful exploitation of this vulnerability could allow an unauthenticated attacker to bypass Tomcat’s security constraints and access protected application resources.
Recommended Actions
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
1. Apply the latest supported security updates for affected Apache Tomcat Software as soon as possible to address these known vulnerabilities.
3. Migrate away from unsupported versions (Tomcat 7.0.x / 8.5.x) to a supported release, since no security fixes are available for end-of-life branches.
4. Before applying updates, ensure that a current and verified backup is available and can be restored if needed.
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.