« Volver al listado

CVE-2026-55956

Estado: AnalizadaMedia (6.5)—

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.

Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-55956",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-55956",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-30T13:23:02.427983Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache Tomcat",
          "versions": [
            {
              "status": "affected",
              "version": "11.0.0-M1",
              "versionType": "semver",
              "lessThanOrEqual": "11.0.22"
            },
            {
              "status": "affected",
              "version": "10.1.0-M1",
              "versionType": "semver",
              "lessThanOrEqual": "10.1.55"
            },
            {
              "status": "affected",
              "version": "9.0.0.M1",
              "versionType": "semver",
              "lessThanOrEqual": "9.0.118"
            },
            {
              "status": "affected",
              "version": "8.5.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.5.100"
            },
            {
              "status": "affected",
              "version": "7.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.109"
            },
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "7.0.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-29T21:16:45.597",
  "references": [
    {
      "url": "https://lists.apache.org/thread/dcjdcnnnww9hhdm016hr0l7hpw1bzjfp",
      "tags": [
        "Vendor Advisory",
        "Mailing List"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/06/29/25",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@apache.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-285"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue."
    }
  ],
  "lastModified": "2026-07-02T19:03:30.203",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BB3B349-8AB6-4C07-B186-888CAFB1609E",
              "versionEndExcluding": "9.0.119"
            },
            {
              "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A8C20B4-DBE1-4890-AD5E-D5EABB6B739D",
              "versionEndExcluding": "10.1.56",
              "versionStartIncluding": "10.1.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C43AD2A0-8785-4A37-AAAE-347B1E0463F1",
              "versionEndExcluding": "11.0.23",
              "versionStartIncluding": "11.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}