Certificate Validation Flaw in Apereo CAS Client by Apereo
CVE-2026-15243
7.4HIGH
What is CVE-2026-15243?
The Apereo CAS Client has a vulnerability where it accepts any CA-trusted certificate for a hostname, provided it matches the configured allowlist or regex. This flaw can be exploited by an attacker in a man-in-the-middle (MITM) position, such as through DNS poisoning or malicious proxies. By presenting a forged but CA-signed certificate that aligns with the allowlist, the attacker could intercept CAS exchanges, capturing sensitive authentication tickets. Although confirmed in specific versions, this issue may extend to other versions of the product, highlighting the need for immediate attention and remediation.
Affected Version(s)
Jasig CAS Client 3.6.4
Java Apereo CAS Client 4.1.0
References
CVSS V4
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafał Łykowski (Qualtrics)
Łukasz Kollbek (Qualtrics)
Krzysztof Surówka (Qualtrics)
