CVE-2026-29146 | Apache Tomcat up to 7.0.109/8.5.100/9.0.115/10.1.52/11.0.18 EncryptInterceptor reliance on obfuscation or encryption of security-relevant inputs without integrity checking (Nessus ID 305904)
A vulnerability, which was classified as problematic, was found in Apache Tomcat up to 7.0.109/8.5.100/9.0.115/10.1.52/11.0.18. Affected is an unknown function of the component EncryptInterceptor. The manipulation results in reliance on obfuscation or encryption of security-relevant inputs without integrity checking.
This vulnerability is reported as CVE-2026-29146. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.