
Tungsten Automation Knowledge
A vulnerability scan (Qualys QID 735210) reports CVE-2026-65182 against the Apache Tomcat 9.0 instance installed with eCopy ShareScan. The finding is rated Important by the Apache Software Foundation and Critical by Qualys, and it is raised on any ShareScan server running Apache Tomcat 9.0.0-M1 through 9.0.120.
Customers and auditors ask whether eCopy ShareScan is exposed to this security constraint bypass and what remediation is required.
CVE-2026-65182 is a flaw in Apache Tomcat's security constraint processing. Where a constraint for a longer path is defined before a more restrictive constraint for a shorter sub-path, a specially crafted request can circumvent the intended access restrictions and potentially expose protected resources to unauthorized users.
Exploitation requires <security-constraint> entries to be defined in the web application's web.xml, with overlapping path patterns ordered in the specific way that triggers the bypass.
eCopy ShareScan is not affected by CVE-2026-65182. No action is required.
Inspection of all eCopy ShareScan web.xml files shows no <security-constraint> declarations at all. Access control in eCopy ShareScan is enforced at the application layer, not through Tomcat's declarative security constraint mechanism. Since the prerequisite configuration is entirely absent, the attack vector described in CVE-2026-65182 cannot be exercised against the product.
Optional: if your security policy requires the scanner finding to be cleared rather than documented as not applicable, Apache Tomcat can be updated manually to version 9.0.121. Follow the Manual update of Apache Tomcat article below, and confirm the target version against ShareScan: Apache Tomcat version requirements before updating. This is a hardening step to satisfy the scanner, not a fix required for product security.
| Product | Version | Build | Environment | Hardware |
|---|---|---|---|---|
| Kofax eCopy ShareScan | v6.5 - v6.6 | |||
| Tunsten eCopy ShareScan | v6.7 - v2026.3 |
2026-09-16
Manual update of Apache Tomcat
ShareScan: Apache Tomcat version requirements
https://aio-eus-uat-cae-aif-app14-local.redglacier-35d7ee4f.eastus.azurecontainerapps.io/article/46017 | Article 000046017 | Printed Sep 30, 2026