Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
SMG 10.9.2 is not affected by this CVE.The current SMG 10.9.2 version does not use Tomcat versions 11.0.20, 10.1.53, or 9.0.116.