
Tungsten Automation Knowledge
A vulnerability scan (Qualys QID 735238) reports CVE-2026-68763 against the Apache Tomcat 9.0 instance installed with eCopy ShareScan. The finding is rated Important by the Apache Software Foundation and Critical by Qualys, and it is raised on any ShareScan server running Apache Tomcat 9.0.39 through 9.0.120.
Customers and auditors ask whether eCopy ShareScan is exposed to this denial of service condition and what remediation is required.
CVE-2026-68763 is a memory allocation leak in Apache Tomcat's HTTP/2 implementation, specifically in the backlog tracking mechanism. The leak is triggered when an HTTP/2 stream is reset (RST_STREAM). An attacker who repeatedly resets streams can gradually exhaust server memory until an OutOfMemoryError occurs, resulting in a denial of service.
The defect is reachable only through the HTTP/2 protocol handler. Without an active HTTP/2 connector there is no code path to the leaking allocation.
eCopy ShareScan is not affected by CVE-2026-68763. No action is required.
The Tomcat configuration shipped with eCopy ShareScan (server.xml) defines every active Connector with protocol="HTTP/1.1". HTTP/2 support (the Http2Protocol upgrade) is disabled, commented out, in all shipped versions. Because no HTTP/2 connector is active, the attack vector described in CVE-2026-68763 cannot be exercised against the product.
Optional: if your security policy requires the scanner finding to be cleared rather than documented as not applicable, Apache Tomcat can be updated manually to version 9.0.121. Follow the Manual update of Apache Tomcat article below, and confirm the target version against ShareScan: Apache Tomcat version requirements before updating. This is a hardening step to satisfy the scanner, not a fix required for product security.
| Product | Version | Build | Environment | Hardware |
|---|---|---|---|---|
| Kofax eCopy ShareScan | v6.5 - v6.6 | |||
| Tunsten eCopy ShareScan | v6.7 - v2026.3 |
2026-09-16
Manual update of Apache Tomcat
ShareScan: Apache Tomcat version requirements
https://aio-eus-uat-cae-aif-app14-local.redglacier-35d7ee4f.eastus.azurecontainerapps.io/article/46014 | Article 000046014 | Printed Sep 30, 2026