Status: UPDATED | Advisory ID: CVE-2026-86247
| CVE | CVE-2026-86247 |
| CVSS Score / Version | 7.4 (High) / CVSS v3.1 |
| Updated | 2026-09-23 |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CVSS Prose | attack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none. |
| Affected products | Apache Software Foundation Apache Tomcat Native |
| Classified as | CWE-366 (Race Condition within a Thread) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Apache Software Foundation | Apache Tomcat Native |
| Subsystems | General OT |
| Sectors | Multiple |
Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations.
This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Unsupported versions may also be affected.
Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fixes the issue. (NVD)
Monitor Apache Software Foundation's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-86247 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-86247 |