Tungsten Automation Knowledge

ShareScan CVE-2026-65182

000046017 · How To · Last Updated: Sep 16, 2026

Issue

A vulnerability scan (Qualys QID 735210) reports CVE-2026-65182 against the Apache Tomcat 9.0 instance installed with eCopy ShareScan. The finding is rated Important by the Apache Software Foundation and Critical by Qualys, and it is raised on any ShareScan server running Apache Tomcat 9.0.0-M1 through 9.0.120.

Customers and auditors ask whether eCopy ShareScan is exposed to this security constraint bypass and what remediation is required.


 

Cause

CVE-2026-65182 is a flaw in Apache Tomcat's security constraint processing. Where a constraint for a longer path is defined before a more restrictive constraint for a shorter sub-path, a specially crafted request can circumvent the intended access restrictions and potentially expose protected resources to unauthorized users.

  • Affected Apache Tomcat versions: 9.0.0-M1 - 9.0.120
  • Fixed in Apache Tomcat: 9.0.121

Exploitation requires <security-constraint> entries to be defined in the web application's web.xml, with overlapping path patterns ordered in the specific way that triggers the bypass.


 

Solution

eCopy ShareScan is not affected by CVE-2026-65182. No action is required.

Inspection of all eCopy ShareScan web.xml files shows no <security-constraint> declarations at all. Access control in eCopy ShareScan is enforced at the application layer, not through Tomcat's declarative security constraint mechanism. Since the prerequisite configuration is entirely absent, the attack vector described in CVE-2026-65182 cannot be exercised against the product.

Optional: if your security policy requires the scanner finding to be cleared rather than documented as not applicable, Apache Tomcat can be updated manually to version 9.0.121. Follow the Manual update of Apache Tomcat article below, and confirm the target version against ShareScan: Apache Tomcat version requirements before updating. This is a hardening step to satisfy the scanner, not a fix required for product security.


 

Applies to  

ProductVersionBuildEnvironmentHardware
Kofax eCopy ShareScanv6.5 - v6.6
 Tunsten eCopy ShareScan  v6.7 - v2026.3   


 

Request created:

2026-09-16

References

Manual update of Apache Tomcat

ShareScan: Apache Tomcat version requirements

ShareScan: Java requirements 

eCopy ShareScan: Removing Java / ApacheTomcat 

ShareScan Vulnerability overview

Sections recovered from body HTML: issue, cause, solution, applies, refs.

https://aio-eus-uat-cae-aif-app14-local.redglacier-35d7ee4f.eastus.azurecontainerapps.io/article/46017 | Article 000046017 | Printed Sep 30, 2026

Back to the article · use your browser's Print command, or save the PDF.