Intel

AIKIDO-2026-388833

tomcat-embed-core is vulnerable to Access Control Bypass

Access Control BypassCVE-2026-65927 Published Today

75

High Risk

This Affects:

JAVAtomcat-embed-core
8.5.0 - 9.0.120
Fixed in 9.0.121
10.1.0 - 10.1.57
Fixed in 10.1.59
11.0.0 - 11.0.24
Fixed in 11.0.25
Are you affected? Scan for Free

TL;DR

tomcat-embed-core RewriteValve mishandles the [N] flag because of an off-by-one error. Rewrite processing restarts at the second rule instead of the first. The skipped first rule can be an access-control or deny rule, so a request can reach a resource that should have been blocked. The fix resets rewrite processing to the first rule.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and RewriteValve is configured with the [N] flag.

Background info

tomcat-embed-core is vulnerable to Access Control Bypass in versions 8.5.0 - 9.0.120, 10.1.0 - 10.1.57 and 11.0.0 - 11.0.24.

How to fix this

Upgrade the org.apache.tomcat.embed:tomcat-embed-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform