Skip to content

CVE-2026-65182: Security Constraint Order Bypass and Authorization Failure in Apache Tomcat

HERMES

HERMES THREAT SCORE & OPERATIONAL EXPOSURE

Target: Catalina Security Constraint Processing (Apache Tomcat) — Apache Tomcat
Confidence: 95%
92 / 100
CRITICAL

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 19 / 20
Threat Activity 17 / 20
Weaponization 18 / 20
Exposure 18 / 20
Prevalence 19 / 20
Impact 20 / 20
Exploit Maturity 16 / 20
Attack Chain Potential 16 / 20
⚖️ Divergence & Operational Rationale

Hermes rates CVE-2026-65182 at 92 (CRITICAL). When web applications define `<security-constraint>` blocks where a broader pattern appears prior to a stricter nested constraint in `web.xml`, Catalina's URL pattern matcher selects the less restrictive rule. Remote unauthenticated attackers can directly access administrative consoles, APIs, and protected directories without authentication.

HASS

HASS INFRASTRUCTURE & AGENTIC IMPACT POSTURE

Target: Enterprise Tomcat Servers, Management Consoles & Corporate Web Portals
Confidence: 92%
86 / 100
CRITICAL

Measures specific systemic risk arising from autonomy, tool authority, and cascading execution.

Dimension Breakdown
Autonomy 14 / 20
Tool Access 14 / 20
Privilege 17 / 15
Persistence 14 / 15
External Impact 13 / 15
Propagation 13 / 15
⚖️ Divergence & Operational Rationale

Critical enterprise Java applications, microservice clusters, and CI/CD pipelines depend on strict memory and authorization boundaries. Vulnerabilities in core components like Catalina Security Constraint Processing (Apache Tomcat) allow adversaries to break through sandbox isolation and compromise business-critical assets.

🕸️ Connected Knowledge Graph & Provenance

CVE-2026-65182: Security Constraint Order Bypass and Authorization Failure in Apache TomcatVULNERABILITY

Connected Nodes: 1
Active Relationships (Outgoing)
→ affectsPRODUCTApache Tomcat
98% VERY_HIGH

Software platform affected by security vulnerabilities and agentic attack patterns.

🔍 Why is this related? (Evidence & Provenance)

“Confirmed security vulnerability in Apache Tomcat documented in Hermes dossier.”

Supporting Verified Evidence:

1. Technical Context & Affected Software Matrix

Section titled “1. Technical Context & Affected Software Matrix”

The vulnerability CVE-2026-65182 resides in the Catalina Security Constraint Processing (Apache Tomcat) subsystem of Apache Tomcat.

+-----------------------------------------------------------------------------------------+
| JAVA RUNTIME ECOSYSTEM |
| |
| +---------------------------------------------------------------------------------+ |
| | APPLICATION & MICROSERVICE LAYER | |
| | Spring Boot / Quarkus / Micronaut / Web Applications / Custom JVM Services | |
| +---------------------------------------+-----------------------------------------+ |
| | |
| v |
| +---------------------------------------------------------------------------------+ |
| | AFFECTED SUBSYSTEM: Catalina Security Constraint Processing (Apache Tomcat) | |
| | Root Flaw: Incorrect Authorization | |
| +---------------------------------------+-----------------------------------------+ |
| | |
| v |
| +---------------------------------------------------------------------------------+ |
| | OPERATING SYSTEM & CONTAINER ENGINE | |
| | Linux / Windows / Docker / Kubernetes Pod Sandboxes & Native Libraries | |
| +---------------------------------------------------------------------------------+ |
+-----------------------------------------------------------------------------------------+
DimensionSpecification
Vulnerability IdentifierCVE-2026-65182
Component AffectedCatalina Security Constraint Processing (Apache Tomcat)
Primary CWECWE-863 (Incorrect Authorization)
CVSS v3.1 Score & Vector9.1 (CRITICAL) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector / SurfaceAV:N (Unauthenticated, Scope Unchanged (S:U))
Integrity ImpactHigh (Total Integrity Loss / Code Execution)
Confidentiality ImpactHigh (Total Memory / Data Disclosure)
Availability ImpactNone
Affected ReleasesTomcat 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), 7.0.0 through 7.0.109 (EOL)
Recommended Safe Version11.0.25, 10.1.59, 9.0.121

The defect in CVE-2026-65182 is caused by incorrect authorization within Catalina Security Constraint Processing (Apache Tomcat).

When untrusted data or requests reach this component, the missing boundary validation or logic error triggers an unexpected state transition, as depicted in the sequence diagram below:

sequenceDiagram
autonumber
actor Attacker as Threat Actor / Malicious Client
participant Service as Java Host / Gateway
participant Component as Subsystem (Catalina Security Constraint Processing (Apache Tomcat))
participant Target as JVM Memory / Host OS
Attacker->>Service: Dispatch crafted payload (Security Constraint Ordering Bypass / Missing Authentication)
Service->>Component: Forward input to processing pipeline
activate Component
Note over Component: CWE-863: Validation failure / logic defect
Component->>Target: Trigger uncontrolled condition (Confined to JVM Process & Container Sandbox)
deactivate Component
Target-->>Attacker: Exploit effect achieved (Security Constraint Ordering Bypass / Missing Authentication)

Deploy the following detection rules to monitor runtime behavior and identify exploitation attempts against CVE-2026-65182.

title: Suspicious Activity Related to CVE-2026-65182 (Catalina Security Constraint Processing (Apache Tomcat))
id: cve-2026-65182-sigma-detection
status: experimental
description: Detects unusual execution patterns or anomalous errors matching CVE-2026-65182 exploitation.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65182
- https://hermes-codex.dev/cve/2026/cve-2026-65182/
author: Hermes Codex Cyber Threat Intelligence
date: 2026-09-15
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- '/catalina.sh'
selection_child:
Image|endswith:
- '/java'
condition: selection_parent and selection_child
fields:
- CommandLine
- Image
- ParentCommandLine
falsepositives:
- Legitimate administrative maintenance
- Authorized automated deployments
level: high
tags:
- attack.execution
- attack.initial_access
- cve.cve-2026-65182

Network Detection Signature (Suricata / Snort)

Section titled “Network Detection Signature (Suricata / Snort)”
alert tcp any any -> $HOME_NET any (msg:"HERMES-CODEX - Potential CVE-2026-65182 Exploitation Pattern in Catalina Security Constraint Processing (Apache Tomcat)"; flow:to_server,established; content:"|00|"; threshold:type limit, track by_src, count 5, seconds 60; classtype:attempted-admin; sid:2026651821; rev:1; metadata:cve CVE-2026-65182, hermes_threat_score 92;)
rule Hermes_CVE_2026_65182_Artifact {
meta:
description = "Identifies in-memory patterns and exploit strings associated with CVE-2026-65182"
author = "Hermes Codex Research"
cve = "CVE-2026-65182"
severity = "CRITICAL"
date = "2026-09-15"
strings:
$fp1 = "Catalina Security Constraint Processing (Apache Tomcat)" ascii wide
$fp2 = "CWE-863" ascii wide
$magic = "CVE-2026-65182" ascii wide
condition:
all of them
}

4. Remediation, Patching & Defensive Hardening

Section titled “4. Remediation, Patching & Defensive Hardening”
  1. Apply Official Vendor Security Patches: Upgrade your installation of Apache Tomcat to 11.0.25, 10.1.59, 9.0.121 or newer immediately.

  2. Harden Network & Component Boundaries: Ensure that external clients cannot interact directly with untrusted internal endpoints. Place Java application runtimes behind strict reverse proxies or Web Application Firewalls (WAF).

  3. Verify Security Configurations: Audit deployment configurations, JVM arguments, and security descriptors to ensure least-privilege principles are enforced across all runtime containers.


Section titled “5. Related Intelligence & Cross-References”