Knox CVE Database
/
CVE-2026-34486
High
7.5

CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

Added to the CISA KEV catalog:
August 4, 2026

Overview

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.

This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Vulnerability details

Affected vendor
Apache
Affected product
Tomcat
Weakness type (CWE)
CWE-311, CWE-807

CVE-2026-34486 is a missing encryption of sensitive data flaw in Apache Tomcat's session replication channel, classified under CWE-311 and CWE-807. The fix for CVE-2026-29146 introduced a defect that allows the EncryptInterceptor to be bypassed: the component makes an encryption decision based on attacker-influenced input (CWE-807), causing inter-node session data to transit without the encryption the EncryptInterceptor is configured to provide. The flaw is present in specific point releases and requires that session replication with EncryptInterceptor be configured on the target instance.


An attacker sends crafted input directed at the Tomcat session replication channel or the associated HTTP interface, triggering the EncryptInterceptor bypass and exposing plaintext session data that should have been encrypted. In isolation, the gain is high-confidentiality-impact access to sensitive session material. CISA notes this vulnerability can be chained with CVE-2025-24813: SOCRadar's analysis of the SNOWLIGHT campaign documents confirmed exploitation against government infrastructure in this chained configuration, delivering the SNOWLIGHT malware family and web-shell implants. Exploitation requires the target to run one of the three affected point releases with EncryptInterceptor-enabled clustering configured.

Severity and impact

7.5
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
None
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Audit Tomcat cluster configuration files (server.xml, context.xml) for EncryptInterceptor presence alongside affected version strings (11.0.20, 10.1.53, or 9.0.116); a node running these versions with EncryptInterceptor declared is exposed.
  • Monitor Tomcat access logs for unexpected partial PUT requests or session-related endpoints consistent with CVE-2025-24813 activity immediately following anomalous cluster replication traffic, as the chained attack path produces both signals in sequence.
  • Review deployed JSP files and web application directories for newly written shell files with no corresponding deployment event; the SNOWLIGHT campaign placed Neo-reGeorg web shells over pre-existing JSP implants on compromised Tomcat instances.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 7, 2026

Additional hardening

  • Restrict cluster replication port access (default 4000/tcp) to known cluster member IP addresses via host firewall or network ACL, preventing external nodes from reaching the replication channel.
  • If EncryptInterceptor is not operationally required, disable session replication clustering entirely until patched versions are deployed, eliminating the attack surface.
  • Apply network segmentation so Tomcat nodes handling session replication are not directly reachable from internet-facing segments; place a layer-4 control between public ingress and cluster ports.
  • Disable partial PUT support in Tomcat configuration if not required by the application, reducing exposure to the CVE-2025-24813 chained deserialization path.

Key dates

Published (NVD)
April 9, 2026
Added to CISA KEV
August 4, 2026
Remediation deadline
August 7, 2026
Last updated
August 10, 2026

References

Frequently asked questions

Does CVE-2026-34486 affect my FedRAMP authorization?

If Apache Tomcat runs inside your authorization boundary, CVE-2026-34486 affects your FedRAMP authorization directly. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 7, 2026. An unpatched KEV inside your boundary is an assessor finding: you either remediate it or formally document a mitigation before your assessor or sponsoring agency raises it first.

How does Knox help me handle CVE-2026-34486?

Remediating Apache Tomcat is your responsibility under the FedRAMP shared-responsibility model. Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to help you document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-34486 surfaces, exposure is identified through ongoing monitoring rather than surfacing only when an assessor flags it at review time, giving your team time to act before it becomes a formal finding.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-34486 isn't remediated by August 7, 2026?

If you miss the August 7, 2026 deadline, CVE-2026-34486 becomes a Plan of Action and Milestones (POA&M) item. A longer POA&M list turns a routine continuous-monitoring review into a tough agency conversation. Hitting the deadline keeps your authorization clean and your agency relationship strong.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting