CVE-2026-86247 Apache Tomcat Native - Client certificate requirements
can be down-graded
Severity: Moderate
Vendor: The Apache Software Foundation
Versions Affected:
Apache Tomcat Native 2.0.0 to 2.0.15
Apache Tomcat Native 1.3.0 to 1.3.8
Older, EOL versions may also be affected
Description:
A race condition allowed client certificate verification requirements to
be down-graded for some configurations.
Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat Native 2.0.16 or later
- Upgrade to Apache Tomcat Native 1.3.9 or later
History:
2026-09-23 Original advisory
References:
[1] https://tomcat.apache.org/security-native