CVE-2026-65183

Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.


We have discovered 2,466 live websites that are affected by CVE-2026-65183.

Run a Free Instant Scan




Affected Software

Product  Apache Tomcat
Category Web Servers
Vulnerable Domains2,466 live websites (35% of Apache Tomcat install base)
Vulnerable Versions
  • from 9.0.42 through 9.0.120
  • from 10.1 through 10.1.57
  • from 11 through 11.0.24
Vulnerable Versions Count121 versions ( 32% of all versions)


Common Weakness Enumeration

CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition



Details

  • Published - Aug 25, 2026
  • Updated - Aug 26, 2026

Website Distribution by Country

Number of websites using CVE-2026-65183
United States875 websites



Germany233 websites
China218 websites
France90 websites
Italy86 websites
Hong Kong72 websites
Brazil60 websites
GB58 websites
Netherlands55 websites
India50 websites

Website Distribution by TLD

Number of websites using CVE-2026-65183
.com826 websites
.de178 websites
.edu158 websites
.net94 websites
.org90 websites
.it81 websites
.com.br78 websites
.nl44 websites
.cn43 websites
.cz42 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65183

Top websites that are affected by CVE-2026-65183. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.edu United States***
**.***.*****.*****.***.com United States**,***
*****.********.com United States**,***
*********.**********.com United States**,***
************.com United States**,***
***.*******.com United States**,***
***.*********.edu United States**,***
********.*********.com United States**,***
***.****.edu United States**,***
***.*****.org United States**,***
See full domain list

FAQ

CVE-2026-65183 is Time-of-check Time-of-use (TOCTOU) Race Condition in Apache Tomcat
A total of 2,466 websites have been identified as vulnerable to CVE-2026-65183, based on global website indexing conducted by WebTechSurvey.
The Apache Tomcat is affected by the CVE-2026-65183 vulnerability.
Apache Tomcat versions up to and including 11.0.24 are vulnerable to CVE-2026-65183.