Knox CVE Database
/
CVE-2026-34486
High
7.5

CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

Added to the CISA KEV catalog:
August 4, 2026

Overview

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.

This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Vulnerability details

Affected vendor
Apache
Affected product
Tomcat
Weakness type (CWE)
CWE-311, CWE-807

Apache Tomcat's EncryptInterceptor is a clustering component that encrypts session replication traffic between Tomcat nodes. CVE-2026-34486 arises from a defective fix for a prior Padding Oracle flaw in that interceptor: the corrective code introduced a CWE-807 trust-boundary weakness, meaning the system can be influenced through untrusted input into skipping the encryption decision entirely. The result is CWE-311: sensitive session data that should be encrypted in transit between cluster members flows in plaintext. The flaw is present only in the three specific point releases that carried the flawed prior fix.

An attacker with network access to an affected Tomcat instance sends crafted inbound requests that exploit the CWE-807 trust-boundary bypass, causing the EncryptInterceptor to be circumvented. The direct gain is high-confidentiality impact: session replication data that should be encrypted is exposed. This flaw is documented as chainable with a separate partial-PUT deserialization vulnerability, where the unencrypted channel or the bypass condition is a prerequisite that extends the attack to remote code execution. Exploitation requires that EncryptInterceptor be configured, meaning clustering and session replication must be active on the target instance.

Severity and impact

7.5
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
None
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Audit Tomcat configuration files (server.xml, context.xml) for EncryptInterceptor presence on versions 11.0.20, 10.1.53, or 9.0.116; any instance with the interceptor configured and running those exact versions is exposed and should be treated as potentially compromised until patched.
  • Review Tomcat cluster replication traffic logs for session data appearing on inter-node communication channels without the expected encrypted framing; plaintext session tokens or serialized objects visible in cluster channel captures indicate the interceptor is not functioning.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 7, 2026

Additional hardening

  • Restrict inter-node cluster replication ports (default 4000 and related multicast addresses) to a dedicated management network segment, preventing external access to the unencrypted channel.
  • Disable clustering and session replication entirely on any Tomcat instance that does not require it, removing the EncryptInterceptor attack surface until patching is complete.
  • Place Tomcat cluster nodes behind a host-based firewall that permits replication traffic only from explicitly enumerated peer IP addresses, blocking any unexpected source from reaching the replication channel.
  • Conduct forensic triage per CISA guidance on affected instances, reviewing access logs and session stores for anomalous deserialization activity or unexpected file writes that may indicate chained exploitation.

Key dates

Published (NVD)
April 9, 2026
Added to CISA KEV
August 4, 2026
Remediation deadline
August 7, 2026
Last updated
August 10, 2026

References

Frequently asked questions

Does CVE-2026-34486 affect my FedRAMP authorization?

If Apache Tomcat runs inside your authorization boundary, yes. CVE-2026-34486 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of August 7, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-34486?

Knox doesn't patch your software for you — remediating Apache Tomcat is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.

What happens if CVE-2026-34486 isn't remediated by August 7, 2026?

It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

What this vulnerability means for your FedRAMP compliance

Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.

FedRAMP remediation deadlines for actively exploited vulnerabilities

FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.

How Knox reduces the burden of CVE vulnerabilities

Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.

How to limit your exposure through inherited controls and isolation

Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting