CVE-2026-59084CWE-1059

Apache Tomcat: EncryptInterceptor requirements not clearly documented

Critical · published July 14, 2026

CVSS v3.1
9.1
EPSS
1%
Percentile
41.3
In the wild
Unconfirmed
What it is

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.

Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

The record
Technical detail
CVSS v3.1
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00506 · 41.3th percentile
Weakness
CWE-1059 · Insufficient Technical Documentation
Published
2026-07-14T08:24Z
EPSS history
Timeline
  • 14 JUL 08:24Z
    Apache Tomcat: EncryptInterceptor requirements not clearly documented
    cvelistv5