CVE-2026-55956

Public on 2026-06-29
Modified on 2026-07-01
Description
Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.

Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core tomcat Pending Fix
Amazon Linux 2 - Tomcat9 Extra tomcat 2026-07-20 ALAS2TOMCAT9-2026-027 Fixed
Amazon Linux 2 - Tomcat8.5 Extra tomcat No Fix Planned
Amazon Linux 2023 tomcat10 2026-07-20 ALAS2023-2026-1946 Fixed
Amazon Linux 2023 tomcat9 2026-07-20 ALAS2023-2026-1945 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N