Race Condition in Tomcat Native <2.0.16/1.3.9: Downgrade Client Cert Verification
CVE-2026-86247 Published on September 23, 2026
Apache Tomcat Native: Client certificate requirements can be down-graded
Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations.
This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Unsupported versions may also be affected.
Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fixes the issue.
Vulnerability Analysis
CVE-2026-86247 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Race Condition within a Thread
If two threads of execution use a resource simultaneously, there exists the possibility that resources may be used while invalid, in turn making the state of execution undefined.
Products Associated with CVE-2026-86247
Want to know whenever a new CVE is published for Apache Tomcat Native? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Tomcat Native:- Version 2.0.0, <= 2.0.15 is affected.
- Version 1.3.0, <= 1.3.8 is affected.