CVE-2026-55276: Apache Tomcat: Logged effective web.xml is incomplete
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.118-0+deb11u1Fixed in 9.0.70-2Fixed in 9.0.95-1Fixed in 9.0.118-1 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.23 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.56 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.119
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55276?
CVE-2026-55276 has a risk rating of 30, indicating a significant impact on security.
How do I fix CVE-2026-55276?
To fix CVE-2026-55276, upgrade your Apache Tomcat to version 11.0.23, 10.1.56, or 9.0.80 or later.
Which Apache Tomcat versions are affected by CVE-2026-55276?
CVE-2026-55276 affects Apache Tomcat versions from 11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, and earlier versions in the 9.0 series.
What specific issue does CVE-2026-55276 address?
CVE-2026-55276 addresses an Always-Incorrect Control Flow Implementation vulnerability that results in incomplete logging of authorization constraints.
How does CVE-2026-55276 impact application security?
CVE-2026-55276 can lead to insufficient authorization visibility, which may expose applications to unauthorized access due to incomplete logging.