cvesecurityvulnerability
CVE-2026-15554: Undertow AJP Authentication Bypass via Forged Client Certificate Attributes
Undertow AJP CLIENT-CERT authentication bypass via forged ssl_cert and is_ssl attributes. An unauthenticated attacker who reaches port 8009 can bypass mutual TLS authentication. Part of the Ghostcat-class AJP trust model flaws.