CVE-2026-59084

tomcat: Insufficient Technical Documentation (CVE-2026-59084)

criticalEPSS 0.5%

Affected

  • bitnami/tomcat 7.0.100..*
  • bitnami/tomcat 10.1.0..*
  • bitnami/tomcat 11.0.0..*

Description

A flaw was found in Apache Tomcat. Insufficient technical documentation regarding the secure configuration of the EncryptInterceptor component may lead to deployments with insecure settings. This vulnerability could allow an attacker to exploit misconfigurations that arise from unclear guidance, potentially compromising the confidentiality or integrity of data processed by the affected system.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

bitnamitomcat
10.1.011.0.07.0.100

Metrics

9.1
Source: nvd-v3
41.4 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-15 16:00 UTC
CWE-1059

Weakness classes (CWE)

  • CWE-1059Class

    Insufficient Technical Documentation

    The product does not contain sufficient technical or engineering documentation (whether on paper or in electronic form) that contains descriptions of all the relevant software/hardware elements of the product, such as its usage, structure, architectural components, interfaces, design, implementation, configuration, operation, etc.

    cwe.mitre.org →

References & sources

Linked advisories