{"id":"CVE-2026-86248","published":"2026-09-23T12:17:08.237","lastModified":"2026-09-23T17:58:26.570","description":"CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121.\n\n\n\nUsers are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-287"],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread/nmkmjp9l53y8h3oc4n8fc0bkw9dv15sk","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows CLIENT_CERT authentication to fail improperly when soft fail is disabled, leading to potential unauthorized access.","exploitability":"Exploitation requires disabling soft fail and may be moderately difficult, depending on the environment configuration.","blast_radius":"If exploited, this could result in unauthorized access to sensitive resources hosted on affected Apache Tomcat versions.","remediation":"Upgrade to Apache Tomcat version 11.0.26, 10.1.60, or 9.0.122.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","web","apache","tomcat"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:50:50.893Z"}}