CVE-2026-76183: Apache Tomcat: Bypass of security constraints for WebSocket endpoints
Apache Tomcat CVE-2026-76183 lets attackers bypass security constraints on any WebSocket endpoint.
Mark Thomas disclosed CVE-2026-76183, rated important, an Authentication Bypass by Alternate Name in Apache Tomcat. Security constraints on any WebSocket endpoint can be bypassed. Affected ranges are Tomcat 11.0.0-M1 through 11.0.25, 10.1.0-M1 through 10.1.59, 9.0.0.M1 through 9.0.121, 8.5.0 through 8.5.100, and 7.0.43 through 7.0.109, plus releases before 7.0.43. The post does not report active exploitation.
- Important-severity authentication bypass of WebSocket security constraints
- Affects Tomcat 7.0.43–7.0.109, 8.5, 9.0, 10.1, and 11.0 through listed builds
- Disclosed by Mark Thomas; no exploitation reported
Vulnerabilities mentionedAll →
- CVE-2026-761839.8—Critical Authentication Bypass in Apache Tomcat WebSocket Endpointspublished · Apache Software Foundation Apache Tomcat
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-76183 | Critical Authentication Bypass in Apache Tomcat WebSocket Endpoints CVE-2026-76183 is a critical authentication bypass vulnerability in Apache Tomcat that allows an attacker to bypass security constraints for any configured WebSocket endpoint. The flaw is triggered by making requests using alternate, malformed hostnames that the server accepts but do not match the intended security constraints. A successful attack grants unauthorized access to protected WebSocket resources without authentication, potentially leading to data exposure or manipulation. This issue affects a wide range of supported and older, unsupported Tomcat versions. As of this analysis, there are no known public exploits or reports of in-the-wild exploitation. Upgrade to Apache Tomcat 11.0.26, 10.1.60, or 9.0.122 immediately. For older, unsupported versions (8.5.x, 7.0.x), upgrade to a supported release. There is no other mitigation for this authentication bypass. |
Posted by Mark Thomas on Sep 23 Severity: important Affected versions: - Apache Tomcat 11.0.0-M1 through 11.0.25 - Apache Tomcat 10.1.0-M1 through 10.1.59 - Apache Tomcat 9.0.0.M1 through 9.0.121 - Apache Tomcat 8.5.0 through 8.5.100 - Apache Tomcat 7.0.43 through 7.0.109 - Apache Tomcat before 7.0.43 Description: Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue...
This source does not provide full text. Read it at seclists.org.