Intel

AIKIDO-2026-10192

tomcat-embed-core is vulnerable to Improper Check for Unusual or Exceptional Conditions

Improper Check for Unusual or Exceptional ConditionsCVE-2024-52316 Published Feb 20, 2026

98

Critical Risk

This Affects:

JAVAtomcat-embed-core
8.5.0 - 9.0.95
Fixed in 9.0.96
10.1.0 - 10.1.29
Fixed in 10.1.30
11.0.0 - 11.0.0
Fixed in 11.0.1
Are you affected? Scan for Free

TL;DR

Apache Tomcat contains an unchecked error condition vulnerability in certain Jakarta Authentication (formerly JASPIC) configurations. If Tomcat uses a custom ServerAuthContext implementation that throws an exception during authentication without explicitly setting an HTTP error status, the authentication process may not fail as intended. As a result, a user could potentially bypass authentication. No known Jakarta Authentication components are currently known to exhibit this behavior.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

tomcat-embed-core is vulnerable to Improper Check for Unusual or Exceptional Conditions in versions 11.0.0 - 11.0.0, 10.1.0 - 10.1.29 and 8.5.0 - 9.0.95.

How to fix this

Upgrade Tomcat to any of the patched versions.