CVE-2026-43512: Apache Tomcat: Digest authenticator will authenticate any unknown user
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tomcat10to a version that resolves this vulnerability.Fixed in 10.1.55-1~deb12u1Fixed in 10.1.55-1~deb13u1Fixed in 10.1.55-1 - Upgrade
Upgrade
debian/tomcat11to a version that resolves this vulnerability.Fixed in 11.0.22-1~deb13u1Fixed in 11.0.22-2 - Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.118-0+deb11u1Fixed in 9.0.70-2Fixed in 9.0.95-1Fixed in 9.0.118-1 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.22 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.55 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.118
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43512?
CVE-2026-43512 is classified as a moderate severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2026-43512?
To fix CVE-2026-43512, upgrade to Apache Tomcat version 11.0.22 or later, 10.1.55 or later, or 9.0.118 or later.
Which versions of Apache Tomcat are affected by CVE-2026-43512?
CVE-2026-43512 affects Apache Tomcat versions from 11.0.0-M1 to 11.0.21, 10.1.0-M1 to 10.1.54, and 9.0.0.M1 to 9.0.117, as well as earlier versions.
What type of vulnerability is CVE-2026-43512?
CVE-2026-43512 is an authentication bypass vulnerability specifically related to the digest authentication mechanism.
Is there any workaround for CVE-2026-43512?
There are no known workarounds for CVE-2026-43512; upgrading to a patched version is the recommended action.