Looking for the vulnerability index of Invicti's legacy products?
Apache Tomcat Improper Authorization Vulnerability - CVE-2026-55956 - Vulnerability Database

Apache Tomcat Improper Authorization Vulnerability - CVE-2026-55956

Medium
Reference: CVE-2026-55956
Title: Apache Tomcat Improper Authorization Vulnerability
Overview:

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22 from 10.1.0-M1 through 10.1.55 from 9.0.0.M1 through 9.0.118 from 8.5.0 through 8.5.100 from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23 10.1.56 or 9.0.119 which fix the issue.