https://seclists.org/oss-sec/2026/q3/583: CVE-2026-65927: Apache Tomcat: writeValve [N] starts at the second rule and may bypass access control
Published Aug 25, 2026
·Updated
Affected Software
4 affected components
Apache Tomcat>=11.0.0-M1<=11.0.24
Apache Tomcat>=10.1.0-M1<=10.1.57
Apache Tomcat>=9.0.0.M1<=9.0.120
Apache Tomcat>=8.5.0<=8.5.100
Frequently Asked Questions
1
Are Tomcat 7 deployments affected?
Tomcat 7.0.0 through 7.0.109 are listed as affected. Versions before 7.0.0 are listed as unaffected.
2
Does the advisory say whether a default Tomcat configuration is vulnerable?
No. The provided advisory does not state whether the affected behavior is enabled or reachable in a default configuration.
3
Does the advisory provide a workaround for environments that cannot update immediately?
No workaround or mitigation is included in the provided advisory.