CVE-2026-18047

MEDIUM CVSS 3.1: 6.5 EPSS 0.28%
Updated Jul 28, 2026
Tomcat
Parameter Value
CVSS 6.5 (MEDIUM)
Type CWE-288 (Authentication Bypass Using Alternate Path)
Vendor Tomcat
Public PoC No

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial of service.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v3.1