Vulnerability in Apereo CAS (August 19, 2026)
A vulnerability has been discovered in Apereo CAS. It allows an attacker to cause a security policy bypass.
CSIRTS triage
- What
- A vulnerability allows attackers to bypass security policy checks in Apereo CAS.
- Who is affected
- Apereo CAS deployments running affected versions.
- Urgency
- High priority; security policy bypass can allow unauthorized access and privilege escalation.
- Action
- Update Apereo CAS to a version that resolves the reported security policy bypass vulnerability.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CAS
Get an email when a new CAS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1043/
Recent advisories for Apereo CAS
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownVulnerability in Apereo CAS (August 26, 2026)cert-fr-avis · 2026-08-26
- unknownCVE-2026-15243: Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the cl…nvd · 2026-07-24
- criticalCVE-2026-59099: Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote un…nvd · 2026-07-02
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Google Chrome (August 26, 2026)2026-08-26
- unknownMultiple vulnerabilities in Apache Tomcat (August 26, 2026)2026-08-26
- unknownMultiple vulnerabilities in Veeam products (August 26, 2026)2026-08-26
- unknownVulnerability in Apereo CAS (August 26, 2026)2026-08-26
- unknownMultiple vulnerabilities in OpenSSL (August 26, 2026)2026-08-26