A high‑severity vulnerability (CVE-2026-34486) has been identified in Apache Tomcat’s EncryptInterceptor component. This flaw allows attackers to bypass encryption between cluster nodes, potentially exposing sensitive data in transit.
Affected Systems:
Apache Tomcat Software: versions 9.0.13 to 9.0.116, 10.1.0-M1 to 10.1.53 and 11.0.0-M1 to 11.0.20
Security Risks
Successful exploitation of this vulnerability could allow an attacker to bypass the EncryptInterceptor, resulting in sensitive data being transmitted without encryption between affected Apache Tomcat cluster nodes. This exposure increases the risk of information disclosure, interception of credentials, and manipulation of application data.
Recommended Actions
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
1. Apply the latest supported security updates for affected Apache Tomcat Software as soon as possible to address the vulnerabilities.