CVE-2026-86247 Apache Tomcat Native - Client certificate requirements can be down-graded

Severity: Moderate

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat Native 2.0.0 to 2.0.15
Apache Tomcat Native 1.3.0 to 1.3.8
Older, EOL versions may also be affected

Description:
A race condition allowed client certificate verification requirements to be down-graded for some configurations.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat Native 2.0.16 or later
- Upgrade to Apache Tomcat Native 1.3.9 or later

History:
2026-09-23 Original advisory

References:
[1] https://tomcat.apache.org/security-native








Reply via email to