CVE-2026-68569

Apache Tomcat: Principal lookup can fail open in some cases

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.


We have discovered 6,224 live websites that are affected by CVE-2026-68569.

Run a Free Instant Scan




Affected Software

Product  Apache Tomcat
Category Web Servers
Vulnerable Domains6,224 live websites (87% of Apache Tomcat install base)
Vulnerable Versions
  • from 7 through 70.109
Vulnerable Versions Count335 versions ( 89% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Aug 25, 2026
  • Updated - Aug 26, 2026

Website Distribution by Country

Number of websites using CVE-2026-68569
United States1,958 websites



China1,363 websites
Germany372 websites
France179 websites
Italy175 websites
Netherlands128 websites
India123 websites
Brazil120 websites
Korea, South119 websites

Website Distribution by TLD

Number of websites using CVE-2026-68569
.com2,655 websites
.cn296 websites
.de244 websites
.net243 websites
.edu202 websites
.org192 websites
.it159 websites
.com.br137 websites
.com.cn106 websites
.nl103 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-68569

Top websites that are affected by CVE-2026-68569. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.edu United States***
**************.com United States**,***
**.***.*****.*****.***.com United States**,***
*****.********.com United States**,***
*********.**********.com United States**,***
**.******.com United States**,***
****.***.uz Uzbekistan**,***
************.com United States**,***
***.*******.com United States**,***
***.*********.edu United States**,***
See full domain list

FAQ

CVE-2026-68569 is Improper Authentication in Apache Tomcat
A total of 6,224 websites have been identified as vulnerable to CVE-2026-68569, based on global website indexing conducted by WebTechSurvey.
The Apache Tomcat is affected by the CVE-2026-68569 vulnerability.
Apache Tomcat versions up to and including 70.109 are vulnerable to CVE-2026-68569.