https://seclists.org/oss-sec/2026/q2/495: CVE-2026-43512: Apache Tomcat: Digest authenticator will authenticate any unknown user
Published May 12, 2026
·Updated
Affected Software
1 affected component
Apache Tomcat>=11.0.0-M1<=11.0.21, >=10.1.0-M1<=10.1.54, >=9.0.0.M1<=9.0.117, >=8.5.0<=8.5.100, >=7.0.0<=7.0.109, <7.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-43512?
The severity of CVE-2026-43512 is classified as moderate.
2
How do I fix CVE-2026-43512?
To fix CVE-2026-43512, update Apache Tomcat to a version that is not affected, such as 11.0.22 or later for Tomcat 11.
3
Which versions of Apache Tomcat are affected by CVE-2026-43512?
CVE-2026-43512 affects Apache Tomcat versions 11.0.0-M1 through 11.0.21, 10.1.0-M1 through 10.1.54, 9.0.0.M1 through 9.0.117, 8.5.0 through 8.5.100, and 7.0.0 through 7.0.109.
4
What is the main issue caused by CVE-2026-43512?
CVE-2026-43512 allows the Digest authenticator to authenticate any unknown user, potentially granting unauthorized access.
5
When was CVE-2026-43512 published?
CVE-2026-43512 was published on May 12, 2026.