CVE-2026-75973

Description

A flaw was found in Apache Tomcat. When Jakarta Authentication is configured with SimpleAuthConfigProvider as the default provider and multiple web applications utilize it, an improper authentication vulnerability arises. This issue causes the authentication realm established for the first web application to be incorrectly applied to all subsequent web applications. Consequently, this could lead to unauthorized access or incorrect authorization decisions across different web applications.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Bypass Protection Mechanism

Frequently Asked Questions

Want to get errata notifications? Sign up here.