Skip to main content

Improper Authorization

CVE-2026-55956

Severity Medium
Score 6.5/10

Summary

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat versions prior to 9.0.119, 10.x prior to 10.1.56 and 11.x prior to 11.0.23. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-285 - Improper Authorization

The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Advisory Timeline

  • Published