Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
[POC] CVE-2026-34486 — CVE-2026-34486
Apache Tomcat Tribes EncryptInterceptor fail-open bypass, unauthenticated RCE PoC
[POC] CVE-2026-34486 — CVE-2026-34486-poc
CVE-2026-34486 Apache Tomcat EncryptInterceptor 绕过漏洞复现(使用GLM5.1复现完成)
[POC] GHSA-652q-gvq3-74qv — cve-2026-34486-tomcat_encrypt_bypass_reproduction
CVE Reproduction: cve-2026-34486-tomcat_encrypt_bypass_reproduction
[POC] CVE-2026-34486 — CVE-2026-34486-Tribes
Tribes 协议探测
[POC] CVE-2026-34486 — CVE-2026-34486
Apache Tomcat EncryptInterceptor Bypass → Unauthenticated RCE (CVE-2026-34486)
[POC] CVE-2026-34486 — tomcat-cve-2026-34486
CVE labs
PoC: CVE-2026-34486---unauthenticated-RCE-via-Java-deserialization
EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free