Vulnerability Description
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | >= 7.0.100, <= 7.0.109 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7MitigationVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/14/8Mailing ListThird Party Advisory
FAQ
What is CVE-2026-59084?
CVE-2026-59084 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: ...
How severe is CVE-2026-59084?
CVE-2026-59084 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-59084?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat.