{"id":"CVE-2026-86247","published":"2026-09-23T13:17:31.237","lastModified":"2026-09-23T19:19:41.923","description":"Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations.\n\n\n\nThis issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Unsupported versions may also be affected.\n\n\n\nUsers are recommended to upgrade to version 2.0.16 or 1.3.9, which fixes the issue.","cvssScore":7.4,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-366"],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread/obsson6zhvfg0wsp2bx602l61ltj87r1","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/09/23/33","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}