Apache Tomcat Improper Privilege Management Vulnerability

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

Published 3 Sep 2026Updated 3 Sep 2026175 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

Affected versions

Tomcat: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 48143Apache Tomcat - AJP 'Ghostcat File Read/InclusionYDHCUI2020-02-20VerifiedExploit-DB 49039Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)SunCSR2020-11-13VerifiedPoC-in-GitHub · xindongzhuaizhuai/CVE-2020-1938★ 45xindongzhuaizhuai2020-02-20CandidatePoC-in-GitHub · sgdream/CVE-2020-1938CVE-2020-1938★ 3sgdream2020-02-20CandidatePoC-in-GitHub · bkfish/CNVD-2020-10487-Tomcat-Ajp-lfi-ScannerCnvd-2020-10487 / cve-2020-1938, scanner tool★ 294bkfish2020-02-20CandidatePoC-in-GitHub · laolisafe/CVE-2020-1938CVE-2020-1938漏洞复现★ 38laolisafe2020-02-21CandidatePoC-in-GitHub · h7hac9/CVE-2020-1938★ 2h7hac92020-02-21CandidatePoC-in-GitHub · sv3nbeast/CVE-2020-1938-Tomact-file_include-file_readTomcat的文件包含及文件读取漏洞利用POC★ 56sv3nbeast2020-02-21CandidatePoC-in-GitHub · fairyming/CVE-2020-1938在一定条件下可执行命令★ 11fairyming2020-02-21CandidatePoC-in-GitHub · dacade/CVE-2020-1938★ 9dacade2020-02-21CandidatePoC-in-GitHub · woaiqiukui/CVE-2020-1938TomcatAjpScanner批量扫描TomcatAJP漏洞★ 15woaiqiukui2020-02-21CandidatePoC-in-GitHub · fatal0/tomcat-cve-2020-1938-check★ 7fatal02020-02-21CandidatePoC-in-GitHub · delsadan/CNVD-2020-10487-Bulk-verificationCNVD-2020-10487 OR CVE-2020-1938 批量验证脚本,批量验证,并自动截图,方便提交及复核★ 3delsadan2020-02-22CandidatePoC-in-GitHub · 00theway/Ghostcat-CNVD-2020-10487Ghostcat read file/code execute,CNVD-2020-10487(CVE-2020-1938)★ 42300theway2020-02-22CandidatePoC-in-GitHub · shaunmclernon/ghostcat-verificationLearnings on how to verify if vulnerable to Ghostcat (aka CVE-2020-1938)★ 1shaunmclernon2020-02-26CandidatePoC-in-GitHub · w4fz5uck5/CVE-2020-1938-Clean-VersionCVE-2020-1938(GhostCat) clean and readable code version★ 6w4fz5uck52020-03-01CandidatePoC-in-GitHub · whatboxapp/GhostCat-LFI-expCVE-2020-1938★ 0whatboxapp2020-03-03CandidatePoC-in-GitHub · Just1ceP4rtn3r/CVE-2020-1938-Tool批量检测幽灵猫漏洞★ 3Just1ceP4rtn3r2020-03-20CandidatePoC-in-GitHub · doggycheng/CNVD-2020-10487CVE-2020-1938 / CNVD-2020-1048 Detection Tools★ 8doggycheng2020-03-27CandidatePoC-in-GitHub · I-Runtime-Error/CVE-2020-1938This is about CVE-2020-1938★ 0I-Runtime-Error2020-05-12CandidatePoC-in-GitHub · Umesh2807/GhostcatCVE-2020-1938 exploit★ 0Umesh28072020-05-12CandidatePoC-in-GitHub · MateoSec/ghostcatchDisables AJP connectors to remediate CVE-2020-1938!★ 0MateoSec2020-07-17CandidatePoC-in-GitHub · acodervic/CVE-2020-1938-MSF-MODULEModified version of auxiliary/admin/http/tomcat_ghostcat, it can Read any file★ 0acodervic2021-02-01CandidatePoC-in-GitHub · Hancheng-Lei/Hacking-Vulnerability-CVE-2020-1938-Ghostcat★ 21Hancheng-Lei2021-03-28CandidatePoC-in-GitHub · streghstreek/CVE-2020-1938★ 1streghstreek2021-04-27CandidatePoC-in-GitHub · Neko-chanQwQ/CVE-2020-1938Scanner for CVE-2020-1938★ 1Neko-chanQwQ2021-07-11CandidatePoC-in-GitHub · jptr218/ghostcatAn implementation of CVE-2020-1938★ 1jptr2182021-08-14CandidatePoC-in-GitHub · YounesTasra-R4z3rSw0rd/CVE-2020-1938This is a modified version of the original GhostCat Exploit★ 3YounesTasra-R4z3rSw0rd2022-08-21CandidatePoC-in-GitHub · tpt11fb/AttackTomcatTomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含★ 258tpt11fb2022-11-13CandidatePoC-in-GitHub · Warelock/cve-2020-1938cve-2020-1938 Tomcat-Ajp-lfi.git脚本★ 2Warelock2024-04-14CandidatePoC-in-GitHub · RedTeam-Rediron/CVE-2020-1938★ 0RedTeam-Rediron2024-08-20CandidatePoC-in-GitHub · lizhianyuguangming/TomcatScanProtomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含★ 296lizhianyuguangming2024-08-29CandidatePoC-in-GitHub · hopsypopsy8/CVE-2020-1938-Exploitation★ 0hopsypopsy82025-02-15CandidatePoC-in-GitHub · abrewer251/CVE-2020-1938_Ghostcat-PoCApache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection capabilities★ 0abrewer2512025-12-11CandidatePoC-in-GitHub · With-fate/CVE-2020-1938Apache Tomcat(CVE-2020-1938)漏洞验证脚本★ 1With-fate2026-04-07CandidatePoC-in-GitHub · sangrok-jeon/CVE-2020-1938-Tomcat-AJP-Ghostcat--AnalysisCVE-2020-1938-Tomcat-AJP(Ghostcat)-Analysis★ 0sangrok-jeon2026-04-08CandidatePoC-in-GitHub · aidilzlkfli/ScanningAnalysis of network scan results, service vulnerabilities, OS fingerprinting, and critical Nessus findings including Ghostcat (CVE-2020-1938).★ 0aidilzlkfli2026-05-06CandidatePoC-in-GitHub · si1ence90/Ghostcat-Tomcat-AJP-Exploit-Py3A fully refactored, Python 3 compatible exploit script for Tomcat Ghostcat (CVE-2020-1938 / CNVD-2020-10487) AJP Local File Inclusion★ 0si1ence902026-05-08CandidatePoC-in-GitHub · cyberguardsec101-sketch/ghostcatCVE-2020-1938 Exploit★ 0cyberguardsec101-sketch2026-05-09CandidatePoC-in-GitHub · duckpigdog/Tomcat-AJP-CVE-2020-1938Tomcat AJP文件读取/包含漏洞★ 0duckpigdog2026-05-25CandidatePoC-in-GitHub · lem0n817/tomcatfilereadCVE-2020-1938 (Ghostcat) Tomcat AJP file read/file include PoC with python3 port★ 0lem0n8172026-09-04Candidate