Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-webappsUpgrade tomcat-admin-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-libUpgrade tomcat-el-3.0-apiUpgrade tomcat-jsvcUpgrade tomcat-docs-webappUpgrade tomcat-servlet-4.0-apiUpgrade tomcat | Jul 16, 2026 | Jul 16, 2026 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 9.0.102Upgrade Apache Tomcat to 10.1.39Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 11.0.5 | Jun 30, 2026 | Jun 29, 2026 |
| Debian | — | Upgrade tomcat9Upgrade tomcat11Upgrade tomcat10 | Jul 1, 2026 | Jul 1, 2026 |
| Redhat_linux | — | Upgrade tomcat9-admin-webappsUpgrade tomcat-libUpgrade tomcat9-jsp-2.3-apiUpgrade tomcat-el-5.0-apiUpgrade tomcat-servlet-4.0-apiUpgrade tomcat9-libNo solution existsUpgrade tomcat9-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-admin-webappsUpgrade tomcat-webappsUpgrade tomcat-docs-webappUpgrade tomcat-servlet-6.0-apiUpgrade tomcat9Upgrade tomcat-el-3.0-apiUpgrade tomcat9-el-3.0-apiUpgrade tomcat9-servlet-4.0-apiUpgrade tomcat-jsp-3.1-apiUpgrade tomcatUpgrade tomcat9-docs-webapp | Aug 17, 2026 | Jun 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub