{"cve":"CVE-2026-76183","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[11.0.0-M1,11.0.25]"}},{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[10.1.0-M1,10.1.59]"}},{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[9.0.0-M1,9.0.121]"}},{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[8.5.0,8.5.100]"}},{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[7.0.43,7.0.109]"}},{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[0,7.0.43)"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"Apache Tomcat","source":"cna","vendor":"Apache Software Foundation"},"product":"tomcat","vendor":"apache"}],"created":"2026-09-23T13:30:05.041025+00:00","updated":"2026-09-23T18:00:07.954733+00:00","vendors":["apache","apache$PRODUCT$tomcat"]},"mitre":{"cpes":[],"created":"2026-09-23T11:16:09.907000+00:00","description":"Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.\n\n\n\nThe following versions were EOS at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\nUsers are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/76xxx/CVE-2026-76183.json","references":["https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp"],"title":"Apache Tomcat: Bypass of security constraints for WebSocket endpoints","updated":"2026-09-23T18:10:41.803000+00:00","vendors":[],"weaknesses":["CWE-289"]},"nvd":{"cpes":[],"created":"2026-09-23T12:17:06.537000+00:00","description":"Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.\n\n\n\nThe following versions were EOS at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\nUsers are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-76183.json","references":["http://www.openwall.com/lists/oss-security/2026/09/23/21","https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp"],"title":null,"updated":"2026-09-23T19:19:14.877000+00:00","vendors":[],"weaknesses":["CWE-289"]},"opencve":{"changes":[{"created":"2026-09-23T11:45:00+00:00","data":[{"details":{"new":"Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.\n\n\n\nThe following versions were EOS at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\nUsers are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.","old":null},"type":"description"},{"details":{"new":"Apache Tomcat: Bypass of security constraints for WebSocket endpoints","old":null},"type":"title"},{"details":{"added":["CWE-289"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp"],"removed":[]},"type":"references"}],"id":"13e8ff35-6460-46fe-a2a2-65a3a7d14a9a"},{"created":"2026-09-23T14:45:00+00:00","data":[{"details":["apache","apache$PRODUCT$tomcat"],"type":"first_time"},{"details":{"added":["apache","apache$PRODUCT$tomcat"],"removed":[]},"type":"vendors"}],"id":"8e3b0f65-5b16-44f6-8920-16590deca11b"},{"created":"2026-09-23T16:30:00+00:00","data":[{"details":{"added":{"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"83432b9a-7472-42a1-8e74-bf87d5a4bf3b"},{"created":"2026-09-23T19:30:00+00:00","data":[{"details":{"added":["http://www.openwall.com/lists/oss-security/2026/09/23/21"],"removed":[]},"type":"references"}],"id":"10a1ef74-7449-41e4-84bf-09975c1db4be"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2026-09-23T11:16:09.907000+00:00","provider":"mitre"},"description":{"data":"Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.\n\n\n\nThe following versions were EOS at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\nUsers are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"vulnrichment"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{},"provider":null},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["http://www.openwall.com/lists/oss-security/2026/09/23/21","https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp"],"providers":["mitre","nvd"]},"title":{"data":"Apache Tomcat: Bypass of security constraints for WebSocket endpoints","provider":"mitre"},"updated":{"data":"2026-09-23T19:19:14.877000+00:00","provider":"nvd"},"vendors":{"data":["apache","apache$PRODUCT$tomcat"],"providers":["enrichment"]},"weaknesses":{"data":["CWE-289"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-09-23T11:16:09.907000+00:00","description":"Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.\n\n\n\nThe following versions were EOS at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\nUsers are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"Apache Tomcat: Bypass of security constraints for WebSocket endpoints","updated":"2026-09-23T15:33:05.471000+00:00","vendors":[],"vulnrichment_repo_path":"2026/76xxx/CVE-2026-76183.json","weaknesses":[]}}