CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication version before 6.3.5.1
Other sources
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
— CISA
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcat 11to a version that resolves this vulnerability.Fixed in 11.0.21 - Upgrade
Upgrade
Apache Tomcat 10to a version that resolves this vulnerability.Fixed in 10.1.54 - Upgrade
Upgrade
Apache Tomcat 9to a version that resolves this vulnerability.Fixed in 9.0.117 - Upgrade
Upgrade
NetIQ Advance Authenticationto a version that resolves this vulnerability.Fixed in 6.3.5.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34486?
CVE-2026-34486 is considered a significant vulnerability affecting Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116.
How do I fix CVE-2026-34486?
To fix CVE-2026-34486, update Apache Tomcat to the latest version that addresses this vulnerability.
Which Apache Tomcat versions are affected by CVE-2026-34486?
CVE-2026-34486 affects Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116.
What does CVE-2026-34486 vulnerability involve?
CVE-2026-34486 involves a bypass of the EncryptInterceptor due to a fix that was implemented for CVE-2026-29146.
Is there a workaround for CVE-2026-34486 until a fix is applied?
Currently, there are no documented workarounds for CVE-2026-34486; applying the fix through an update is recommended.