CVE-2026-68525

Apache Tomcat: Redirect after FORM auth may bypass method specific constraints

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.


We have discovered 5,696 live websites that are affected by CVE-2026-68525.

Run a Free Instant Scan




Affected Software

Product  Apache Tomcat
Category Web Servers
Vulnerable Domains5,696 live websites (80% of Apache Tomcat install base)
Vulnerable Versions
  • from 7 through 7.0.109
  • from 8.5 through 8.5.100
  • from 9 through 9.0.120
  • from 10.1 through 10.1.57
  • from 11 through 11.0.24
Vulnerable Versions Count298 versions ( 79% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Aug 25, 2026
  • Updated - Aug 26, 2026

Credits

  • 4ra1n, pyn3rd and unam4 (finder)

Website Distribution by Country

Number of websites using CVE-2026-68525
United States1,855 websites



China1,180 websites
Germany348 websites
France169 websites
Italy167 websites
Brazil115 websites
India110 websites
GB108 websites
Hong Kong107 websites

Website Distribution by TLD

Number of websites using CVE-2026-68525
.com2,430 websites
.cn268 websites
.de230 websites
.net220 websites
.edu200 websites
.org184 websites
.it155 websites
.com.br136 websites
.com.cn98 websites
.fr77 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-68525

Top websites that are affected by CVE-2026-68525. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.edu United States***
**************.com United States**,***
**.***.*****.*****.***.com United States**,***
*****.********.com United States**,***
*********.**********.com United States**,***
**.******.com United States**,***
************.com United States**,***
***.*******.com United States**,***
***.*********.edu United States**,***
******.com China**,***
See full domain list

FAQ

CVE-2026-68525 is Incorrect Authorization in Apache Tomcat
A total of 5,696 websites have been identified as vulnerable to CVE-2026-68525, based on global website indexing conducted by WebTechSurvey.
The Apache Tomcat is affected by the CVE-2026-68525 vulnerability.
Apache Tomcat versions up to and including 11.0.24 are vulnerable to CVE-2026-68525.