External risk intelligence

Apache Tomcat Client Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-86248

Apache Tomcat is widely deployed as a public-facing web server, application server, or edge gateway. This vulnerability concerns the client certificate authentication mechanism, a feature commonly exposed on internet-facing services to manage identity, making the vulnerable surface public-facing by design in typical deployments.

Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in Apache Tomcat, a widely used server technology. This issue relates to how client certificates are authenticated, potentially allowing unauthorized access if specific security settings are misconfigured. The main concern is to determine if our operations utilize the affected versions of Tomcat and to what extent.

  • Authentication flaw in Tomcat servers.
  • Confirm exposure of Tomcat in our environment.
  • Assess potential impact and manage risk.

Attack Path

How an attacker could exploit the issue

An attacker could potentially reach this vulnerability by interacting with an Apache Tomcat server that has specific authentication configurations. If client certificate authentication is enabled but configured to "soft fail" (meaning it doesn't strictly enforce success), and this soft-fail option is disabled, the server might not properly reject unauthenticated or improperly authenticated clients. This could allow an attacker to bypass expected authentication controls, leading to unauthorized access and potentially severe impacts on confidentiality, integrity, and availability.

  • Entry condition: Unauthenticated network access.
  • Trigger point: Server with disabled soft-fail authentication.
  • Resulting risk: Unauthorized access and data compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Apache Tomcat could allow unauthenticated attackers to bypass client certificate authentication when soft fail is disabled. This may expose sensitive system data or user information when the service is configured to require client certificates for access.

  • Unauthenticated access to sensitive data.
  • Bypassing client certificate authentication.
  • Unauthorized system access or data exposure.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Apache Tomcat, which affects client certificate authentication, is most likely to impact teams managing public-facing web or application servers, potentially including infrastructure, platform, and security operations teams. The first practical step is to identify all instances of the affected Tomcat versions, determine their exposure and criticality, and confirm the accountable owner for remediation.

  • Identify affected Tomcat instances.
  • Verify public exposure and business impact.
  • Plan vendor-supported upgrades.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Apache Tomcat?

Apache Tomcat is an open-source web server and servlet container that runs Java code. It is widely used to host web applications and provide services that handle dynamic content, acting as the foundation for enterprise systems and microservices alike.

What is the vulnerability in CVE-2026-86248?

This CVE involves an authentication weakness classified as CWE-287, or Improper Authentication. Specifically, it relates to how Tomcat processes client certificates. When security settings are configured to reject invalid certificates, a failure in this logic can allow unauthorized requests to bypass the intended authentication check.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a request to a server configured to require client certificates while the 'soft fail' option is disabled. It is important to note that if your server is not using client certificate authentication, or if it is configured to allow soft failures, it may not be susceptible to this specific bypass path.

Is my server at risk according to Halo Surface Signal?

Halo Surface Signal indicates this vulnerability is very likely to impact systems because Apache Tomcat is frequently deployed as a public-facing web or edge server. Since this bug affects client certificate authentication—a mechanism often used to secure internet-facing services—systems exposed to the network are at higher risk.

What should I do if I run Apache Tomcat?

Your first step is to perform an inventory to identify if you are running any of the affected versions (11.0.x, 10.1.x, or 9.0.x ranges listed in the advisory). Once identified, plan to upgrade to the patched versions—11.0.26, 10.1.60, or 9.0.122—as these releases contain the necessary fixes for this issue.

References