[SECURITY] CVE-2026-68525 Apache Tomcat - Redirect after FORM authentication may bypass method specific constraints

Mark Thomas <[email protected]>
Newsgroups gmane.comp.jakarta.tomcat.devel
Message-ID <[email protected]>
CVE-2026-68525 Apache Tomcat - Redirect after FORM authentication may 
bypass method specific constraints

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.24
Apache Tomcat 10.1.0-M1 to 10.1.57
Apache Tomcat 9.0.0.M1 to 9.0.120

Description:
The FORM authentication process allowed the bypassing of a security 
constraint that limited user access to a resource POST but not GET.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Remove the examples web application
- Upgrade to Apache Tomcat 11.0.25
- Upgrade to Apache Tomcat 10.1.59
- Upgrade to Apache Tomcat 9.0.121

Note: This issue was fixed in Apache Tomcat 10.1.58 but the release vote 
for the 10.1.58 release candidate did not pass. Therefore, although 
users must download 10.1.59 to obtain a version that includes a fix for 
this issue, version 10.1.58 is not included in the list of affected 
versions.

Credit:
This issue was identified by:
- 4ra1n, pyn3rd and unam4

History:
2026-08-25 Original advisory

References:
[1] https://tomcat.apache.org/security-11.html
[2] https://tomcat.apache.org/security-10.html
[3] https://tomcat.apache.org/security-9.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.