<Vulnerability name="CVE-2026-55956">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-06-29T20:46:02</PublicDate>
    <Bugzilla id="2494676" url="https://bugzilla.redhat.com/show_bug.cgi?id=2494676" xml:lang="en:us">
tomcat: Apache Tomcat: Improper Authorization Allows Security Constraint Bypass
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>6.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-551</CWE>
    <Details xml:lang="en:us" source="Mitre">
Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.

Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Apache Tomcat where access control rules for the default servlet are improperly handled. An attacker can exploit this issue to bypass specific HTTP method restrictions, potentially gaining unauthorized access to protected application resources.
    </Details>
    <Statement xml:lang="en:us">
A security flaw in Apache Tomcat allows an attacker to bypass specific HTTP method restrictions on the default servlet. Red Hat products utilizing affected Tomcat versions are vulnerable if they rely on these method-specific security constraints. This could potentially enable unauthorized access to restricted application resources.
    </Statement>
    <Mitigation xml:lang="en:us">
Review your application's web.xml file. Ensure security constraints explicitly deny unauthorized users by path, rather than relying strictly on filtering specific HTTP methods (like GET or POST).
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:jboss_enterprise_web_server:7.0">
        <ProductName>Red Hat JBoss Web Server 7.0.0</ProductName>
        <ReleaseDate>2026-07-14T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:39189">RHSA-2026:39189</Advisory>
        <Package name="tomcat-catalina">tomcat-catalina</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10">
        <ProductName>Red Hat JBoss Web Server 7.0 on RHEL 10</ProductName>
        <ReleaseDate>2026-07-14T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:39188">RHSA-2026:39188</Advisory>
        <Package name="jws7-tomcat">jws7-tomcat-0:11.0.21-5.redhat_00004.1.el10jws</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8">
        <ProductName>Red Hat JBoss Web Server 7.0 on RHEL 8</ProductName>
        <ReleaseDate>2026-07-14T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:39188">RHSA-2026:39188</Advisory>
        <Package name="jws7-tomcat">jws7-tomcat-0:11.0.21-5.redhat_00004.1.el8jws</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9">
        <ProductName>Red Hat JBoss Web Server 7.0 on RHEL 9</ProductName>
        <ReleaseDate>2026-07-14T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:39188">RHSA-2026:39188</Advisory>
        <Package name="jws7-tomcat">jws7-tomcat-0:11.0.21-5.redhat_00004.1.el9jws</Package>
    </AffectedRelease>
    <AffectedRelease impact="critical" cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-06-24T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:29203">RHSA-2026:29203</Advisory>
        <Package name="tomcat10-main">tomcat10-main-10.1.56-1.hum1</Package>
    </AffectedRelease>
    <AffectedRelease impact="critical" cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-06-29T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:32960">RHSA-2026:32960</Advisory>
        <Package name="tomcat11-main">tomcat11-main-11.0.23-0.1.hum1</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>tomcat</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>tomcat9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>tomcat6</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>tomcat</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>pki-deps:10.6/pki-servlet-engine</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>tomcat</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>pki-servlet-engine</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>tomcat</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_web_server:5">
        <ProductName>Red Hat JBoss Web Server 5</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>jws5-tomcat</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_web_server:6">
        <ProductName>Red Hat JBoss Web Server 6</ProductName>
        <FixState>Affected</FixState>
        <PackageName>tomcat-catalina</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-55956
https://nvd.nist.gov/vuln/detail/CVE-2026-55956
https://lists.apache.org/thread/dcjdcnnnww9hhdm016hr0l7hpw1bzjfp
    </References>
</Vulnerability>