Get instant answers to issues or questions anytime - try our new AI Support Assistant.×

ShareScan - CVE-2026-65927

Home›Search›ShareScan - CVE-2026-65927

ShareScan - CVE-2026-65927

Last Updated: Sep 16, 2026|2 minute read|000046015
#ShareScan#Knowledge#How To

Issue

A vulnerability scan (Qualys QID 735207) reports CVE-2026-65927 against the Apache Tomcat 9.0 instance installed with eCopy ShareScan. The finding is rated Important by the Apache Software Foundation and Critical by Qualys, and it is raised on any ShareScan server running Apache Tomcat 9.0.0-M1 through 9.0.120.

Customers and auditors ask whether eCopy ShareScan is exposed to this access control bypass and what remediation is required.


 

Cause

CVE-2026-65927 is an off-by-one error in Apache Tomcat's RewriteValve. The [N] (next) flag caused rule processing to restart from the second rule instead of the first. Where rewrite rules were used to enforce access control, a specially crafted request could bypass the control implemented by the first rule.

  • Affected Apache Tomcat versions: 9.0.0-M1 - 9.0.120
  • Fixed in Apache Tomcat: 9.0.121

Exploitation requires the RewriteValve to be explicitly declared and active, with rewrite rules in place. Tomcat does not enable the RewriteValve by default; it has to be configured manually.


 

Solution

eCopy ShareScan is not affected by CVE-2026-65927. No action is required.

Inspection of the shipped configuration confirms that:

  • No RewriteValve declaration exists in any eCopy ShareScan server.xml
  • No rewrite.config file is present in the configuration
  • Tomcat does not enable the RewriteValve by default

Because the RewriteValve is neither configured nor active, the attack vector described in CVE-2026-65927 cannot be exercised against the product.

Optional: if your security policy requires the scanner finding to be cleared rather than documented as not applicable, Apache Tomcat can be updated manually to version 9.0.121. Follow the Manual update of Apache Tomcat article below, and confirm the target version against ShareScan: Apache Tomcat version requirements before updating. This is a hardening step to satisfy the scanner, not a fix required for product security.


 

Applies to  

ProductVersionBuildEnvironmentHardware
Kofax eCopy ShareScanv6.5 - v6.6
 Tunsten eCopy ShareScan  v6.7 - v2026.3   


 

Request created:

2026-09-16

References

Manual update of Apache Tomcat

ShareScan: Apache Tomcat version requirements

ShareScan: Java requirements 

eCopy ShareScan: Removing Java / ApacheTomcat 

ShareScan Vulnerability overview

Was this topic helpful? Like Dislike