External risk intelligence

Tomcat Authentication Bypass via Alternate Name Affects WebSockets.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-76183

Apache Tomcat is a widely used web server and servlet container that is commonly deployed as an internet-facing application server, gateway, or component of public-facing web applications to serve web content and API endpoints.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An authentication bypass vulnerability was discovered in Apache Tomcat, a widely used web server, that could allow unauthorized access to WebSocket endpoints. This issue may affect many internet-facing applications and services that rely on Tomcat for handling web content and API requests.

  • Unauthorized access to secure endpoints.
  • Widely used web server technology.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could bypass security controls on WebSocket connections in Apache Tomcat. This bypass allows an unauthenticated attacker to access restricted WebSocket endpoints, potentially leading to unauthorized data access, modification, or denial of service.

  • No authentication needed to begin.
  • Bypassing security constraints on WebSockets.
  • Unauthorized access to restricted data.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to bypass security constraints on WebSocket endpoints in Apache Tomcat. When supported by the advisory's context, this bypass could lead to unauthorized access to sensitive system data or manipulation of service behavior.

  • Unauthorized access to system data.
  • Bypassing security constraints via WebSocket.
  • Potential for data exposure or service disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Apache Tomcat, which allows for authentication bypass of WebSocket endpoints, likely requires action from application owners and infrastructure teams responsible for managing Tomcat deployments. The initial practical move is to identify all instances of the affected Tomcat versions, determine their exposure and business criticality, and then confirm the accountable owner for each instance before planning remediation.

  • Identify and confirm ownership for Tomcat instances.
  • Verify exposure and business criticality of deployments.
  • Plan vendor coordination and targeted upgrades.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Apache Tomcat?

Apache Tomcat is an open-source web server and servlet container. It provides a runtime environment for Java-based code, enabling developers to run web applications and handle incoming network requests. Organizations frequently use it to power public-facing APIs, serve dynamic web content, or act as a gateway that facilitates communication between clients and backend services.

How does CVE-2026-76183 cause an authentication bypass?

This vulnerability is classified as CWE-289, or Authentication Bypass by Alternate Name. It occurs because the server incorrectly validates the identity of a client attempting to connect to a WebSocket endpoint. By manipulating how the connection is named or requested, an attacker can trick the server into treating an unauthorized connection as valid, effectively skipping the security checks that should have protected that specific endpoint.

When does this vulnerability trigger?

The issue triggers when an attacker initiates a WebSocket connection to an Apache Tomcat server configured with specific security constraints. It is important to note that this is not a general failure of all authentication; standard HTTP traffic or endpoints that do not utilize the WebSocket protocol may not be affected by this specific bypass mechanism.

Is my deployment at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a high-priority concern because Apache Tomcat is commonly deployed as an internet-facing application server. Because the vulnerability is reachable over a network without requiring prior authentication, any Tomcat instance exposed to the public internet is considered to have a higher likelihood of risk compared to those restricted to internal, private networks.

Do I need to update my software to fix this?

Yes. The primary path to resolution is upgrading to the patched versions provided by the vendor, such as 11.0.26, 10.1.60, or 9.0.122. Before applying these updates, you should inventory your environment to locate all running Tomcat instances, confirm who owns or manages them, and assess which ones are internet-facing to prioritize your patching schedule.

References