A vulnerability scan (Qualys QID 735207) reports CVE-2026-65927 against the Apache Tomcat 9.0 instance installed with eCopy ShareScan. The finding is rated Important by the Apache Software Foundation and Critical by Qualys, and it is raised on any ShareScan server running Apache Tomcat 9.0.0-M1 through 9.0.120.
Customers and auditors ask whether eCopy ShareScan is exposed to this access control bypass and what remediation is required.
CVE-2026-65927 is an off-by-one error in Apache Tomcat's RewriteValve. The [N] (next) flag caused rule processing to restart from the second rule instead of the first. Where rewrite rules were used to enforce access control, a specially crafted request could bypass the control implemented by the first rule.
Exploitation requires the RewriteValve to be explicitly declared and active, with rewrite rules in place. Tomcat does not enable the RewriteValve by default; it has to be configured manually.
eCopy ShareScan is not affected by CVE-2026-65927. No action is required.
Inspection of the shipped configuration confirms that:
RewriteValve declaration exists in any eCopy ShareScan server.xmlrewrite.config file is present in the configurationBecause the RewriteValve is neither configured nor active, the attack vector described in CVE-2026-65927 cannot be exercised against the product.
Optional: if your security policy requires the scanner finding to be cleared rather than documented as not applicable, Apache Tomcat can be updated manually to version 9.0.121. Follow the Manual update of Apache Tomcat article below, and confirm the target version against ShareScan: Apache Tomcat version requirements before updating. This is a hardening step to satisfy the scanner, not a fix required for product security.
| Product | Version | Build | Environment | Hardware |
|---|---|---|---|---|
| Kofax eCopy ShareScan | v6.5 - v6.6 | |||
| Tunsten eCopy ShareScan | v6.7 - v2026.3 |
2026-09-16
Manual update of Apache Tomcat
ShareScan: Apache Tomcat version requirements