All vulnerabilities

CVE-2026-43512

Apache Tomcat - Digest authenticator will authenticate any unknown user

Description

Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.21 Apache Tomcat 10.1.0-M1 to 10.1.54 Apache Tomcat 9.0.0.M1 to 9.0.117 Older, unsupported versions may also be affected

Description: When DIGEST authentication was configured, any user not known to the configured Realm would be authenticated if they presented the password "null".

Mitigation: Users of the affected versions should apply one of the following mitigations:

  • Upgrade to Apache Tomcat 11.0.22 or later
  • Upgrade to Apache Tomcat 10.1.55 or later
  • Upgrade to Apache Tomcat 9.0.118 or later

Patch Available

Fix available through Seal Security. No upgrade required, protect your application instantly.

Fix without upgrading
Score
9.8
Severity
Critical
Ecosystem
Java
Publish Date
May 12, 2026
Modified Date
May 19, 2026
Score Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Versions