Certificate Validation Flaw in Apereo CAS Client by Apereo
CVE-2026-15243

7.4HIGH

Key Information:

Vendor

Apereo

Vendor
CVE Published:
24 July 2026

What is CVE-2026-15243?

The Apereo CAS Client has a vulnerability where it accepts any CA-trusted certificate for a hostname, provided it matches the configured allowlist or regex. This flaw can be exploited by an attacker in a man-in-the-middle (MITM) position, such as through DNS poisoning or malicious proxies. By presenting a forged but CA-signed certificate that aligns with the allowlist, the attacker could intercept CAS exchanges, capturing sensitive authentication tickets. Although confirmed in specific versions, this issue may extend to other versions of the product, highlighting the need for immediate attention and remediation.

Affected Version(s)

Jasig CAS Client 3.6.4

Java Apereo CAS Client 4.1.0

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafał Łykowski (Qualtrics)
Łukasz Kollbek (Qualtrics)
Krzysztof Surówka (Qualtrics)
.