CVE-2026-34500 | Apache Tomcat up to 9.0.116/10.1.53/11.0.20 CLIENT_CERT Authentication improper authentication
A vulnerability classified as critical was found in Apache Tomcat up to 9.0.116/10.1.53/11.0.20. This vulnerability affects unknown code of the component CLIENT_CERT Authentication. Such manipulation leads to improper authentication.
This vulnerability is listed as CVE-2026-34500. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.