Authentication Bypass by Primary Weakness Affecting org.apache.tomcat.embed:tomcat-embed-core package, versions [9.0.0.M1, 9.0.121)[10.1.0-M1, 10.1.59)[11.0.0-M1, 11.0.25)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.46% (38th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHETOMCATEMBED-20302889
  • published30 Sept 2026
  • disclosed26 Aug 2026
  • creditUnknown

Introduced: 26 Aug 2026

CVE-2026-68569  (opens in a new tab)
CWE-305  (opens in a new tab)

How to fix?

Upgrade org.apache.tomcat.embed:tomcat-embed-core to version 9.0.121, 10.1.59, 11.0.25 or higher.

Overview

org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation.

Affected versions of this package are vulnerable to Authentication Bypass by Primary Weakness in the authentication process when using certain authentication mechanisms such as CLIENT-CERT or SPNEGO. An attacker can gain unauthorized access by authenticating with credentials that do not correspond to a valid user in the DataSourceRealm.

Note: This issue was fixed in Apache Tomcat 10.1.58 but the release vote for the 10.1.58 release candidate did not pass. Therefore, although users must download 10.1.59 to obtain a version that includes a fix for this issue, version 10.1.58 is not included in the list of affected versions.

CVSS Base Scores

version 4.0
version 3.1