logo

CVE-2026-34486: Apache Tomcat Tribes Regression Creates Unauthenticated RCE Path

ID: 84cf5666-f244-5b41-8e84-5a9073c1d1eb

STIX ID: report--84cf5666-f244-5b41-8e84-5a9073c1d1eb

Feed Name: SOCRadar Blog

Threat Score
70/100

Date Published: 2026-04-14

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

CVE-2026-34486 is a regression in Apache Tomcat Tribes where EncryptInterceptor can forward attacker-controlled bytes after decryption failures, allowing those bytes to reach an unfiltered Java deserialization path and potentially enable unauthenticated RCE on affected Tomcat 9.0.116, 10.1.53, and 11.0.20 installations that have Tribes clustering and EncryptInterceptor enabled; fixes are available in 9.0.117, 10.1.54, and 11.0.21 and defenders should patch or restrict access to the Tribes receiver (TCP/4000) and add detection for decrypt failure logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.