CVE-2026-59084

Apache Tomcat: EncryptInterceptor requirements not clearly documented

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.


We have discovered 4,824 live websites that are affected by CVE-2026-59084.

Run a Free Instant Scan




Affected Software

Product  Apache Tomcat
Category Web Servers
Vulnerable Domains4,824 live websites (60% of Apache Tomcat install base)
Vulnerable Versions
  • from 7.0.100 through 7.0.109
  • from 8.5.38 through 8.5.100
  • from 9.0.13 through 9.0.119
  • from 10.1 through 10.1.56
  • from 11 through 11.0.23
Vulnerable Versions Count207 versions ( 54% of all versions)


Common Weakness Enumeration

CWE-1059 Insufficient Technical Documentation



Details

  • Published - Jul 14, 2026
  • Updated - Jul 14, 2026

Credits

  • NDIx (reporter)

Website Distribution by Country

Number of websites using CVE-2026-59084
United States1,727 websites



China771 websites
Germany347 websites
France147 websites
Italy143 websites
Brazil116 websites
GB106 websites
Hong Kong92 websites
Canada88 websites

Website Distribution by TLD

Number of websites using CVE-2026-59084
.com1,934 websites
.de243 websites
.edu226 websites
.net180 websites
.org170 websites
.cn163 websites
.com.br134 websites
.it124 websites
.com.cn75 websites
.fr59 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-59084

Top websites that are affected by CVE-2026-59084. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.edu United States***
**************.com United States**,***
**.***.*****.*****.***.com United States**,***
*****.********.com United States**,***
**.******.com United States**,***
************.com United States**,***
***.*******.com United States**,***
***.*********.edu United States**,***
******.com China**,***
********.*********.com United States**,***
See full domain list

FAQ

CVE-2026-59084 is Insufficient Technical Documentation in Apache Tomcat
A total of 4,824 websites have been identified as vulnerable to CVE-2026-59084, based on global website indexing conducted by WebTechSurvey.
The Apache Tomcat is affected by the CVE-2026-59084 vulnerability.
Apache Tomcat versions up to and including 11.0.23 are vulnerable to CVE-2026-59084.