{"id":"CVE-2026-86246","published":"2026-09-23T13:17:31.117","lastModified":"2026-09-23T19:19:41.770","description":"Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default  including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX.\n\n\n\nThis issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected.\n\n\n\nUsers are recommended to upgrade to version 2.0.16 or 1.3.9, which fix the issue.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-1188"],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread/dgyvfwb24nbk45ptvlhdyhdhl5o7k5ol","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/09/23/32","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows attackers to manipulate SSL/TLS renegotiation and encryption settings, potentially leading to unauthorized access or data exposure.","exploitability":"Exploitation is moderately difficult as it requires specific SSL/TLS renegotiation conditions to be met, and the attacker must have network access to the target.","blast_radius":"If exploited, the vulnerability could lead to data breaches or unauthorized access to sensitive information hosted on the affected Apache Tomcat Native version.","remediation":"Upgrade to Apache Tomcat Native version 2.0.16 or 1.3.9, which address the issue.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["ssl","tls","tomcat","encryption","network"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:52:04.274Z"}}