Apache Tomcat CLIENT_CERT auth bypass when soft fail disabled (v11.0.25)
CVE-2026-86248 Published on September 23, 2026
Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121.
Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Products Associated with CVE-2026-86248
Want to know whenever a new CVE is published for Apache Tomcat? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Tomcat:- Version 11.0.0-M14, <= 11.0.25 is affected.
- Version 10.1.22, <= 10.1.59 is affected.
- Version 9.0.92, <= 9.0.121 is affected.