Apache Tomcat Vulnerability Allows Bypass of Access Controls

Apache Tomcat Vulnerability Allows Bypass of Access Controls

First seen 21 Feb 2026, 04:19 UTC CybersecuritynewsEsecurityplanet 29.9

Article Content

Browse articles
ThreatCluster

Apache disclosed a vulnerability in Tomcat (CVE-2026-24733) that allows attackers to bypass access controls through legacy HTTP/0.9 requests under specific configurations. This low-severity issue was identified by the Apache Tomcat security team and affects systems using certain access-control rules. The original advisory was published on February 17, 2026.

Timeline

2026-02-17
CVE-2026-24733 published
2026-02-20
Cybersecuritynews article published
2026-02-21
Esecurityplanet article published