Response playbooks, investigation guides, and Atomic Red Team tests are Pro-only. Upgrade to unlock the full detection package for CVE-2026-34486.

Unlock with Pro - from £29/user/mo
CVE-2026-34486 Splunk · SPL

Detect Apache Tomcat Missing Encryption of Sensitive Data (CVE-2026-34486) in Splunk

Detects potential exploitation or exposure conditions related to CVE-2026-34486, an Apache Tomcat vulnerability (CWE-311: Missing Encryption of Sensitive Data) allowing sensitive data such as credentials, session identifiers, or configuration secrets to be transmitted or stored without adequate encryption. Actively exploited and listed in CISA KEV; associated with CISA BOD 26-04 prioritized remediation guidance. Detection focuses on plaintext transmission of Tomcat-managed credentials/session tokens over unencrypted channels, anomalous access to Tomcat configuration files (server.xml, context.xml, tomcat-users.xml, web.xml) containing sensitive data, and network indicators of cleartext protocol usage to Tomcat listener ports.

MITRE ATT&CK

Tactic
Credential Access Collection Initial Access

SPL Detection Query

Splunk (SPL)
spl
index=* sourcetype=tomcat_access OR sourcetype=linux_secure OR sourcetype=wineventlog
| eval is_config_access=if(match(_raw, "(?i)(tomcat-users\.xml|server\.xml|context\.xml|web\.xml)"), 1, 0)
| eval is_cleartext=if(match(_raw, "(?i)http://.*:(8080|8009|80)/"), 1, 0)
| where is_config_access=1 OR is_cleartext=1
| stats count min(_time) as first_seen max(_time) as last_seen by host, user, uri, _raw
| where count > 0
high severity medium confidence

Searches Tomcat access logs, auth logs, and Windows event logs for access to sensitive configuration files or cleartext HTTP requests to Tomcat listener ports, indicating potential exposure or exploitation of missing-encryption weaknesses per CVE-2026-34486.

Data Sources

Tomcat Access LogsLinux Auth LogsWindows Security Event Logs

Required Sourcetypes

tomcat_accesslinux_securewineventlog

False Positives & Tuning

  • Normal application log entries referencing config filenames in error messages
  • Health-check probes hitting Tomcat on cleartext ports in segmented internal networks
  • Log aggregation tools ingesting config file contents for backup purposes

Other platforms for CVE-2026-34486


Testing Methodology

Validate this detection against 4 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Simulate cleartext credential exposure in tomcat-users.xml

    Expected signal: File creation and read events for tomcat-users.xml containing plaintext credential strings

  2. Test 2Simulate cleartext HTTP request to Tomcat port

    Expected signal: Network connection event to destination port 8080 using HTTP protocol without TLS

  3. Test 3Simulate access to Tomcat server.xml configuration file

    Expected signal: DeviceProcessEvents/DeviceFileEvents showing PowerShell reading server.xml with connector definitions

  4. Test 4Simulate AJP cleartext connector probe

    Expected signal: Network connection attempt logged to destination port 8009 (AJP) without TLS negotiation

Unlock playbooks & atomic tests with Pro

Get the full detection package for CVE-2026-34486 — response playbook and atomic red team tests, plus investigation guidance and hunting queries.

df00tech Pro — £29/user/month

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections