CVE-2026-86247: Apache Tomcat Native: Client certificate requirements can be down-graded
Apache Tomcat Native CVE-2026-86247 can downgrade client-certificate checks via a race condition.
Mark Thomas disclosed CVE-2026-86247, a moderate-severity race condition in Apache Tomcat Native. Versions 2.0.0 through 2.0.15 and 1.3.0 through 1.3.8 are affected, and unsupported releases may be as well. In some configurations, the flaw can downgrade client-certificate verification requirements. The notice does not report observed exploitation.
- CVE-2026-86247 is rated moderate by the Tomcat project.
- Affects Tomcat Native 2.0.0-2.0.15 and 1.3.0-1.3.8.
- A race condition can weaken client-certificate checks in some setups.
- Unsupported versions may also be affected; no exploitation is reported.
Vulnerabilities mentionedAll →
- CVE-2026-862477.4—Race Condition in Apache Tomcat Native Weakens TLS Client Certificate Verificationpublished · Apache Software Foundation Apache Tomcat Native
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86247 | Race Condition in Apache Tomcat Native Weakens TLS Client Certificate Verification Apache Tomcat Native (tc-native), the optional JNI library that lets Tomcat's APR/native connector use OpenSSL, contains a thread-level race condition (CWE-366) that can cause client certificate verification requirements to be downgraded for some configurations. If the race is won during TLS handshake processing, a server configured to require a valid client certificate (mutual TLS) may accept a connection without proper certificate verification, allowing an unauthenticated remote attacker to reach or impersonate clients on an endpoint that should have been protected. The flaw affects Tomcat Native 1.3.0 through 1.3.8 and 2.0.0 through 2.0.15, and unsupported older versions may also be affected; exploitation requires a vulnerable connector configuration plus favorable timing (reflected in the high attack-complexity CVSS score of 7.4). The impact is on confidentiality and integrity of mutually authenticated services, not availability. No public proof of concept is known, the issue is not on CISA's KEV list, and there are no reports of exploitation in the wild. |
Posted by Mark Thomas on Sep 23 Severity: moderate Affected versions: - Apache Tomcat Native 2.0.0 through 2.0.15 - Apache Tomcat Native 1.3.0 through 1.3.8 Description: Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Unsupported versions may also be affected....
This source does not provide full text. Read it at seclists.org.