CRITICAL
9.8 CVE-2026-76183 Published 23 Sept 2026
Apache Tomcat WebSocket Authentication Bypass Vulnerability
Worried this affects your website?
Apache Tomcat is affected by an Authentication Bypass by Alternate Name vulnerability that allows the security constraints for any WebSocket endpoint to be bypassed.
Affected versions include:
- 11.0.0-M1 through 11.0.25
- 10.1.0-M1 through 10.1.59
- 9.0.0.M1 through 9.0.121
- 8.5.0 through 8.5.100 (EOS at time of CVE creation)
- 7.0.43 through 7.0.109 (EOS at time of CVE creation)
Users are recommended to upgrade to version 11.0.26, 10.1.60, or 9.0.122, which fix the issue.
Reference: CVE-2026-76183 on NVD
← Back to Security News