Tomcat6: Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed…
A vulnerability in Apache Tomcat's JNDIRealm authentication using GSSAPI allows attackers to bypass password verification. This affects multiple Tomcat versions from 7.0.0 through 11.0.4. Upgrading to versions 11.0.5, 10.1.37, or 9.0.101 resolves the issue.
AI Analysis
Technical Summary
Apache Tomcat contains a missing critical step in the authentication process when the JNDIRealm is configured to authenticate binds using GSSAPI. This flaw permits attackers to authenticate without providing the correct password. The vulnerability affects Apache Tomcat versions from 11.0.0-M1 through 11.0.4, 10.1.0-M1 through 10.1.36, 9.0.0.M1 through 9.0.100, 8.5.0 through 8.5.100, and 7.0.0 through 7.0.109. The issue is fixed in versions 11.0.5, 10.1.37, and 9.0.101.
Potential Impact
Attackers can bypass authentication and gain unauthorized access to systems using affected Apache Tomcat versions configured with JNDIRealm and GSSAPI. This compromises confidentiality, integrity, and availability of the affected systems.
Mitigation Recommendations
Users should upgrade Apache Tomcat to version 11.0.5, 10.1.37, or 9.0.101 or later to remediate this vulnerability. Patch status is confirmed with official fixes available in these versions.
Tomcat6: Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed…
Description
A vulnerability in Apache Tomcat's JNDIRealm authentication using GSSAPI allows attackers to bypass password verification. This affects multiple Tomcat versions from 7.0.0 through 11.0.4. Upgrading to versions 11.0.5, 10.1.37, or 9.0.101 resolves the issue.
CVSS v3.1
Score 7.3high
Affected software
pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps-legacy/xenialpkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm4?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache Tomcat contains a missing critical step in the authentication process when the JNDIRealm is configured to authenticate binds using GSSAPI. This flaw permits attackers to authenticate without providing the correct password. The vulnerability affects Apache Tomcat versions from 11.0.0-M1 through 11.0.4, 10.1.0-M1 through 10.1.36, 9.0.0.M1 through 9.0.100, 8.5.0 through 8.5.100, and 7.0.0 through 7.0.109. The issue is fixed in versions 11.0.5, 10.1.37, and 9.0.101.
Potential Impact
Attackers can bypass authentication and gain unauthorized access to systems using affected Apache Tomcat versions configured with JNDIRealm and GSSAPI. This compromises confidentiality, integrity, and availability of the affected systems.
Mitigation Recommendations
Users should upgrade Apache Tomcat to version 11.0.5, 10.1.37, or 9.0.101 or later to remediate this vulnerability. Patch status is confirmed with official fixes available in these versions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-55957
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a58b47468715ace43d8d5ea
Added to database: 07/16/2026, 10:37:40 UTC
Last enriched: 07/30/2026, 11:17:17 UTC
Last updated: 07/31/2026, 19:24:49 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.