{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/undertow/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-15554"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Undertow"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authentication-bypass","network-security"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-15554 is a critical authentication bypass vulnerability affecting the AJP (Apache Jserv Protocol) listener within Red Hat's Undertow web server. The flaw arises because the listener honors the 'ssl_cert' and 'is_ssl' attributes provided within an incoming AJP request packet without requiring a pre-shared secret or cryptographic validation.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker who can establish a direct TCP connection to the AJP port (default 8009) can inject a forged X.509 certificate into these headers. Because the server trusts these forged attributes, it incorrectly assumes the connection is secured via a valid client certificate, allowing the attacker to bypass CLIENT-CERT authentication requirements. This is particularly dangerous in environments where internal or management interfaces rely on AJP-based mutual TLS for access control. Defenders should prioritize limiting access to port 8009 to trusted, internal-only infrastructure components such as reverse proxies.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to bypass CLIENT-CERT authentication, potentially granting unauthorized access to administrative or restricted application endpoints. This vulnerability exposes services relying on certificate-based identity verification, which could lead to unauthorized data access or service manipulation within affected Red Hat Undertow deployments. The CVSS base score of 7.4 reflects the high impact on confidentiality and integrity for exposed application components.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict network access to the AJP listener (default port 8009) to only authorized, trusted reverse proxy IP addresses.\u003c/li\u003e\n\u003cli\u003ePatch affected Undertow versions immediately upon vendor release.\u003c/li\u003e\n\u003cli\u003eAudit network egress and ingress for traffic targeting TCP port 8009 to identify unauthorized sources or unexpected AJP request patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T09:50:14Z","date_published":"2026-08-11T09:39:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-undertow-ajp-auth-bypass/","summary":"The Undertow AJP listener incorrectly trusts ssl_cert and is_ssl attributes within the AJP protocol without validating a shared secret, allowing unauthenticated attackers to bypass CLIENT-CERT authentication.","title":"Undertow AJP Authentication Bypass via CVE-2026-15554","url":"https://feed.craftedsignal.io/briefs/2026-08-undertow-ajp-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Undertow","version":"https://jsonfeed.org/version/1.1"}