CVE-2026-65182
Publication date 25 August 2026
Last updated 2 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| tomcat6 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Needs evaluation
|
|
| tomcat7 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
|
| tomcat8 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| tomcat9 | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| tomcat10 | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy | Not in release | |
| tomcat11 | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release |
Notes
ebarretto
xenial tomcat6 only builds libservlet2.5-java, not the Tomcat server binaries bionic tomcat7 only builds libservlet3.0-java, not the Tomcat server binaries xenial tomcat6 only builds libservlet2.5-java, not the Tomcat server binaries bionic tomcat7 only builds libservlet3.0-java, not the Tomcat server binaries xenial tomcat6 only builds libservlet2.5-java, not the Tomcat server binaries bionic tomcat7 only builds libservlet3.0-java, not the Tomcat server binaries
Severity score breakdown
CVSS version: CVSS v3.0
Base score
9.1 · Critical
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-65182
- https://github.com/apache/tomcat/commit/8bafd79a3b54684e80e9cb1bafd4746aede7d3f5 (11.0.25)
- https://github.com/apache/tomcat/commit/b79752d2a8578d94743e2a95c50af297f780c0df (10.1.58)
- https://github.com/apache/tomcat/commit/b2c56ec8f20c66773a1a813034ffcdb60841f1cf (9.0.121)