CVE-2026-59084: Apache Tomcat: EncryptInterceptor requirements not clearly documented
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.24 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.57 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.120
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59084?
CVE-2026-59084 is rated with a risk score of 30, indicating a significant vulnerability.
How do I fix CVE-2026-59084?
To fix CVE-2026-59084, ensure you refer to the latest security documentation for configuring the EncryptInterceptor in Apache Tomcat.
Which versions of Apache Tomcat are affected by CVE-2026-59084?
CVE-2026-59084 affects Apache Tomcat versions from 11.0.0-M1 to 11.0.23, 10.1.0-M1 to 10.1.56, and 9.0.13 to 9.0.119 as well as previous versions.
What type of vulnerability is CVE-2026-59084?
CVE-2026-59084 is classified as an Insufficient Technical Documentation vulnerability.
Why is CVE-2026-59084 a concern for Apache Tomcat users?
CVE-2026-59084 is a concern because it involves unclear documentation on securely configuring the EncryptInterceptor, which may lead to misconfigurations.