[SECURITY] CVE-2026-68569 Apache Tomcat - Principal lookup can fail open in some cases

Mark Thomas <[email protected]>
Newsgroups gmane.comp.jakarta.tomcat.devel
Message-ID <c7759736-9ce5-4342-b541-39d1f1586eb5__43942.214134016$1787693876$gmane$org@apache.org>
CVE-2026-68569 Apache Tomcat - Principal lookup can fail open in some cases

Severity: Important

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.24
Apache Tomcat 10.1.0-M1 to 10.1.57
Apache Tomcat 9.0.0.M1 to 9.0.120

Description:
For some authentication methods (e.g. CLIENT-CERT, SPNEGO), a user would 
be authenticated even if the user did not exist in the DataSourceRealm 
or JDBCRealm.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Remove the examples web application
- Upgrade to Apache Tomcat 11.0.25
- Upgrade to Apache Tomcat 10.1.59
- Upgrade to Apache Tomcat 9.0.121

Note: This issue was fixed in Apache Tomcat 10.1.58 but the release vote 
for the 10.1.58 release candidate did not pass. Therefore, although 
users must download 10.1.59 to obtain a version that includes a fix for 
this issue, version 10.1.58 is not included in the list of affected 
versions.

History:
2026-08-25 Original advisory

References:
[1] https://tomcat.apache.org/security-11.html
[2] https://tomcat.apache.org/security-10.html
[3] https://tomcat.apache.org/security-9.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.