← Back to search

CVE-2026-76183

9.8 CRITICAL

Published 2026-09-23 · Updated 2026-09-23

AI risk analysis

Summary
This flaw allows authentication bypass for WebSocket endpoints, enabling unauthorized access. It matters because it can lead to full compromise of the application and system.
Exploitability
Exploitation is relatively easy given the alternate name vulnerability, requiring only knowledge of the alternate name to bypass security constraints.
Blast radius
If exploited, this can result in unauthorized access to sensitive WebSocket endpoints, potentially leading to data theft or system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Apache Tomcat version 11.0.26, 10.1.60, or 9.0.122, which address the issue.
auth-bypasswebwebsockettomcat

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-289

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.