Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default (CVE-2026-29146)
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0 through 11.0.18, from 10.0.0 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
AI Analysis
Technical Summary
CVE-2026-29146 identifies a Padding Oracle vulnerability in the EncryptInterceptor component of Apache Tomcat. This vulnerability arises from weaknesses in the encryption padding mechanism used by EncryptInterceptor in its default configuration, potentially allowing remote attackers to decrypt sensitive data. The affected versions span multiple major releases of Apache Tomcat: from 7.0.100 to 7.0.109, 8.5.38 to 8.5.100, 9.0.13 to 9.0.115, 10.0.0-M1 to 10.1.52, and 11.0.0-M1 to 11.0.18. Red Hat's advisory clarifies that this vulnerability is not exploitable in their supported products due to the lack of support for Tomcat clustering, which is the feature that uses EncryptInterceptor. Mitigation can be achieved by removing the catalina-tribes.jar file from the Tomcat installation if clustering is not required, noting that enabling clustering after this removal may cause service errors. Official fixes are available in Apache Tomcat versions 11.0.19, 10.1.53, and 9.0.116. The CVSS v3.1 base score is 7.5 (high severity), reflecting network attack vector, low complexity, no privileges or user interaction required, unchanged scope, and high confidentiality impact without integrity or availability impact.
Potential Impact
The vulnerability allows a remote attacker to decrypt sensitive information by exploiting the padding oracle weakness in the EncryptInterceptor component of Apache Tomcat. This compromises confidentiality but does not affect integrity or availability. Red Hat products are not vulnerable in practice because Tomcat clustering is unsupported and untested in their distributions, effectively mitigating the risk in those environments.
Mitigation Recommendations
Red Hat advises that this vulnerability is not exploitable in their supported products due to the lack of support for Tomcat clustering. For environments where Tomcat clustering is not used, the vulnerability can be mitigated by removing the affected jar file (catalina-tribes.jar) from the Tomcat installation. This can be done by stopping the Tomcat service, deleting the jar file, and restarting the service. If clustering is enabled, it should be disabled before applying this mitigation to avoid service errors. Additionally, upgrading to Apache Tomcat versions 11.0.19, 10.1.53, or 9.0.116, which include the official fix, is recommended.
Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default (CVE-2026-29146)
Description
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0 through 11.0.18, from 10.0.0 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
Affected software
pkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm4?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-29146 identifies a Padding Oracle vulnerability in the EncryptInterceptor component of Apache Tomcat. This vulnerability arises from weaknesses in the encryption padding mechanism used by EncryptInterceptor in its default configuration, potentially allowing remote attackers to decrypt sensitive data. The affected versions span multiple major releases of Apache Tomcat: from 7.0.100 to 7.0.109, 8.5.38 to 8.5.100, 9.0.13 to 9.0.115, 10.0.0-M1 to 10.1.52, and 11.0.0-M1 to 11.0.18. Red Hat's advisory clarifies that this vulnerability is not exploitable in their supported products due to the lack of support for Tomcat clustering, which is the feature that uses EncryptInterceptor. Mitigation can be achieved by removing the catalina-tribes.jar file from the Tomcat installation if clustering is not required, noting that enabling clustering after this removal may cause service errors. Official fixes are available in Apache Tomcat versions 11.0.19, 10.1.53, and 9.0.116. The CVSS v3.1 base score is 7.5 (high severity), reflecting network attack vector, low complexity, no privileges or user interaction required, unchanged scope, and high confidentiality impact without integrity or availability impact.
Potential Impact
The vulnerability allows a remote attacker to decrypt sensitive information by exploiting the padding oracle weakness in the EncryptInterceptor component of Apache Tomcat. This compromises confidentiality but does not affect integrity or availability. Red Hat products are not vulnerable in practice because Tomcat clustering is unsupported and untested in their distributions, effectively mitigating the risk in those environments.
Mitigation Recommendations
Red Hat advises that this vulnerability is not exploitable in their supported products due to the lack of support for Tomcat clustering. For environments where Tomcat clustering is not used, the vulnerability can be mitigated by removing the affected jar file (catalina-tribes.jar) from the Tomcat installation. This can be done by stopping the Tomcat service, deleting the jar file, and restarting the service. If clustering is enabled, it should be disabled before applying this mitigation to avoid service errors. Additionally, upgrading to Apache Tomcat versions 11.0.19, 10.1.53, or 9.0.116, which include the official fix, is recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-29146
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a58b4d868715ace43dabc09
Added to database: 07/16/2026, 10:39:20 UTC
Last enriched: 08/17/2026, 19:22:07 UTC
Last updated: 09/14/2026, 10:01:30 UTC
Views: 51
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.