CVE-2026-43515: Apache Tomcat: Security constraints not correctly applied
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tomcat10to a version that resolves this vulnerability.Fixed in 10.1.55-1~deb12u1Fixed in 10.1.55-1~deb13u1Fixed in 10.1.55-1 - Upgrade
Upgrade
debian/tomcat11to a version that resolves this vulnerability.Fixed in 11.0.22-1~deb13u1Fixed in 11.0.22-2 - Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.118-0+deb11u1Fixed in 9.0.70-2Fixed in 9.0.95-1Fixed in 9.0.118-1 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.22 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.55 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.118 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-43515
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43515?
CVE-2026-43515 has been classified as a medium severity vulnerability due to improper authorization in Apache Tomcat.
How do I fix CVE-2026-43515?
To fix CVE-2026-43515, upgrade to Apache Tomcat versions 11.0.22, 10.1.55, 9.0.118, 8.5.101, or 7.0.110 or later.
What systems are affected by CVE-2026-43515?
CVE-2026-43515 affects Apache Tomcat versions from 11.0.0-M1 to 11.0.21, 10.1.0-M1 to 10.1.54, 9.0.0-M1 to 9.0.117, and others.
What are the potential risks of CVE-2026-43515?
The risks of CVE-2026-43515 include unauthorized access and manipulation of resources due to improper authorization enforcement.
Is there a workaround for CVE-2026-43515 if I can't upgrade?
While upgrading is the recommended solution for CVE-2026-43515, temporarily restricting HTTP methods can act as a workaround until an upgrade can be performed.