CVE-2026-24733 | Apache Tomcat up to 8.5.100/9.0.112/10.1.49/11.0.14 HEAD Request access control
A vulnerability was found in Apache Tomcat up to 8.5.100/9.0.112/10.1.49/11.0.14. It has been rated as critical. The impacted element is an unknown function of the component HEAD Request Handler. Performing a manipulation results in improper access controls. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2026-24733. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.