Apereo Vulnerabilities and Affected Products
Vulnerabilities associated with Java Apereo CAS Client.
Products
Clear product- CAS8 vulnerabilities
- cas_server2 vulnerabilities
- central_authentication_service1 vulnerability
- Jasig CAS Client1 vulnerability
- Java Apereo CAS Client1 vulnerability
- phpCAS1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-15243HIGH | Improper Validation of Certificate in CAS ClientApereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker with a MITM position (DNS poisoning, rogue Wi-Fi, malicious proxy, etc.) can provide any CA-signed certificate for a hostname that matches the configured allowlist or regex. This can lead to intercepting the CAS exchange, capturing the Ticket-Granting Ticket (TGT), and subsequently obtaining Service Tickets on behalf of the victim. … CWE-297Jul 24, 2026 | CVSS7.4v4.0 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |