Apache Tomcat: Logged effective web.xml is incomplete (CVE-2026-55276)
Apache Tomcat versions 8.5.0 through 8.5.100, 9.0.0 through 9.0.118, 10.1.0 through 10.1.55, and 11.0.0 through 11.0.22 have a vulnerability where the effective web.xml logged by the server is incomplete. Specifically, special roles and empty authorization constraints are omitted from the logged configuration, which can reduce auditability of authorization settings. This issue has been fixed in versions 8.5.101, 9.0.119, 10.1.56, and 11.0.23. Users are advised to upgrade to these fixed versions to resolve the issue.
AI Analysis
Technical Summary
CVE-2026-55276 is an Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat that causes the effective web.xml configuration logged by the server to be incomplete. The flaw omits special roles and empty authorization constraints from the logged output, potentially hiding authorization constraints from audit logs. This affects Apache Tomcat versions from 8.5.0 through 8.5.100, 9.0.0 through 9.0.118, 10.1.0 through 10.1.55, and 11.0.0 through 11.0.22. The issue is resolved by upgrading to versions 8.5.101, 9.0.119, 10.1.56, or 11.0.23. The vendor advisory from Ubuntu confirms the availability of patches and recommends standard system updates or Ubuntu Pro ESM for fixes.
Potential Impact
The vulnerability causes incomplete logging of the effective web.xml configuration, specifically omitting special roles and empty authorization constraints. This reduces the ability to audit authorization settings accurately, potentially allowing attackers or administrators to hide authorization constraints from logs. There is no indication that this directly enables unauthorized access or code execution, but it impacts security monitoring and audit capabilities.
Mitigation Recommendations
A fix is available. Users should upgrade Apache Tomcat to versions 8.5.101, 9.0.119, 10.1.56, or 11.0.23 or later. Ubuntu users can apply the patches via standard system updates or through Ubuntu Pro Extended Security Maintenance (ESM) channels as detailed in the Ubuntu advisory USN-8551-1. No additional mitigation steps are required beyond applying the official patches.
Apache Tomcat: Logged effective web.xml is incomplete (CVE-2026-55276)
Description
Apache Tomcat versions 8.5.0 through 8.5.100, 9.0.0 through 9.0.118, 10.1.0 through 10.1.55, and 11.0.0 through 11.0.22 have a vulnerability where the effective web.xml logged by the server is incomplete. Specifically, special roles and empty authorization constraints are omitted from the logged configuration, which can reduce auditability of authorization settings. This issue has been fixed in versions 8.5.101, 9.0.119, 10.1.56, and 11.0.23. Users are advised to upgrade to these fixed versions to resolve the issue.
Affected software
pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps-legacy/xenialpkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm4?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-55276 is an Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat that causes the effective web.xml configuration logged by the server to be incomplete. The flaw omits special roles and empty authorization constraints from the logged output, potentially hiding authorization constraints from audit logs. This affects Apache Tomcat versions from 8.5.0 through 8.5.100, 9.0.0 through 9.0.118, 10.1.0 through 10.1.55, and 11.0.0 through 11.0.22. The issue is resolved by upgrading to versions 8.5.101, 9.0.119, 10.1.56, or 11.0.23. The vendor advisory from Ubuntu confirms the availability of patches and recommends standard system updates or Ubuntu Pro ESM for fixes.
Potential Impact
The vulnerability causes incomplete logging of the effective web.xml configuration, specifically omitting special roles and empty authorization constraints. This reduces the ability to audit authorization settings accurately, potentially allowing attackers or administrators to hide authorization constraints from logs. There is no indication that this directly enables unauthorized access or code execution, but it impacts security monitoring and audit capabilities.
Mitigation Recommendations
A fix is available. Users should upgrade Apache Tomcat to versions 8.5.101, 9.0.119, 10.1.56, or 11.0.23 or later. Ubuntu users can apply the patches via standard system updates or through Ubuntu Pro Extended Security Maintenance (ESM) channels as detailed in the Ubuntu advisory USN-8551-1. No additional mitigation steps are required beyond applying the official patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-55276
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a58b47868715ace43d97da5
Added to database: 07/16/2026, 10:37:44 UTC
Last enriched: 09/08/2026, 15:03:09 UTC
Last updated: 09/14/2026, 22:01:35 UTC
Views: 29
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.