CVE-2026-34486 | Apache Tomcat up to 9.0.116/10.1.53/11.0.20 missing encryption (Nessus ID 305883 / WID-SEC-2026-1038)
A vulnerability marked as problematic has been reported in Apache Tomcat up to 9.0.116/10.1.53/11.0.20. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing encryption of sensitive data.
This vulnerability is referenced as CVE-2026-34486. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.