Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
We have discovered 6,224 live websites that are affected by CVE-2026-68569.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 6,224 live websites (87% of Apache Tomcat install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 335 versions ( 89% of all versions) |
| 1,958 websites | |
| 1,363 websites | |
| 372 websites | |
| 179 websites | |
| 175 websites | |
| 128 websites | |
| 123 websites | |
| 120 websites | |
| 119 websites |
| .com | 2,655 websites |
| .cn | 296 websites |
| .de | 244 websites |
| .net | 243 websites |
| .edu | 202 websites |
| .org | 192 websites |
| .it | 159 websites |
| .com.br | 137 websites |
| .com.cn | 106 websites |
| .nl | 103 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.***.edu | *** | ||
| **************.com | **,*** | ||
| **.***.*****.*****.***.com | **,*** | ||
| *****.********.com | **,*** | ||
| *********.**********.com | **,*** | ||
| **.******.com | **,*** | ||
| ****.***.uz | **,*** | ||
| ************.com | **,*** | ||
| ***.*******.com | **,*** | ||
| ***.*********.edu | **,*** |
FAQ