CVE-2026-68525

CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may bypass method specific constraints

Vendor Apache Software Foundation
Product Apache Tomcat
Weakness CWE-863 · Incorrect authorization
Published August 25, 2026
Last update August 25, 2026

CVSS base score

What the vulnerability does

01Description

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

Key dates

02Disclosure timeline

August 25, 2026 CVE published

Related vulnerabilities

04Related CVE