Apache Tomcat EncryptInterceptor Insufficient Docs 7.0-11.0.23
CVE-2026-59084 Published on July 14, 2026
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
Vulnerability Analysis
CVE-2026-59084 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Incomplete Documentation
The documentation, whether on paper or in electronic form, does not contain descriptions of all the relevant elements of the product, such as its usage, structure, interfaces, design, implementation, configuration, operation, etc.
Products Associated with CVE-2026-59084
stack.watch emails you whenever new vulnerabilities are published in Apache Tomcat or F5 Networks Tomcat. Just hit a watch button to start following.
Affected Versions
Apache Software Foundation Apache Tomcat:- Version 11.0.0-M1, <= 11.0.23 is affected.
- Version 10.1.0-M1, <= 10.1.56 is affected.
- Version 9.0.13, <= 9.0.119 is affected.
- Version 8.5.38, <= 8.5.100 is affected.
- Version 7.0.100, <= 7.0.109 is affected.