Apache Tomcat 9.0.92 < 9.0.117 Improper Authentication Vulnerability (CVE-2026-34500)

medium Nessus Plugin ID 307003

Version 1.4

Aug 11, 2026, 3:40 PM

  • Detection (removed cve's outside of affected range)
  • Logic Changes (did some stuff)

Plugin Feed: 202608111540

Version 1.3

Aug 5, 2026, 2:08 AM

  • CISA reference
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:F/RL:OF/RC:C")
  • CVSS temporal metrics ("CVSSv3 temporal vector" set to "CVSS:3.0/E:F/RL:O/RC:C")

Plugin Feed: 202608050208

Version 1.2

May 14, 2026, 3:47 AM

  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:POC/RL:OF/RC:C")
  • CVSS temporal metrics ("CVSSv3 temporal vector" set to "CVSS:3.0/E:P/RL:O/RC:C")
  • Exploit attributes ("Exploit available" set to "True")
  • Exploit attributes ("Exploitability ease" changed from "No known exploits are available" to "Exploits are available")

Plugin Feed: 202605140347

Version 1.1

Apr 17, 2026, 3:03 PM

  • New

Plugin Feed: 202604171503

* Changelogs are generally available for changes made after Nov 1, 2022