Intel

AIKIDO-2026-116174

tomcat-embed-core is vulnerable to Authentication Bypass

Authentication BypassCVE-2026-68569 Published Today

81

High Risk

This Affects:

JAVAtomcat-embed-core
7.0.0 - 9.0.120
Fixed in 9.0.121
10.1.0 - 10.1.57
Fixed in 10.1.59
11.0.0 - 11.0.24
Fixed in 11.0.25
Are you affected? Scan for Free

TL;DR

tomcat-embed-core DataSourceRealm can fail open for some authenticators such as CLIENT-CERT and SPNEGO. A user is treated as authenticated even when that user does not exist in the configured database. That grants access without a matching realm entry. The fix rejects authentication when the principal cannot be found in the DataSourceRealm.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and DataSourceRealm is used with CLIENT-CERT or SPNEGO authentication.

Background info

tomcat-embed-core is vulnerable to Authentication Bypass in versions 7.0.0 - 9.0.120, 10.1.0 - 10.1.57 and 11.0.0 - 11.0.24.

How to fix this

Upgrade the org.apache.tomcat.embed:tomcat-embed-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform