PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-79577 fangtang7 CVE debrief

A critical vulnerability in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request. This issue has a CVSS score of 9.8 and is considered CRITICAL. Defenders responsible for sso-master v1.0.0 systems, particularly those exposed to the internet, should assess their exposure and implement compensating controls. The CVE record and NVD detail page provide information on the vulnerability, but additional verification is required to determine the scope of affected systems and remediation steps.

Vendor
fangtang7
Product
sso-master
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-08
Original CVE updated
2026-09-14
Advisory published
2026-09-08
Advisory updated
2026-09-14

Who should care

Defenders responsible for sso-master v1.0.0 systems, particularly those exposed to the internet, should assess their exposure and implement compensating controls.

Why it matters

CVE-2026-79577 is a critical vulnerability in sso-master v1.0.0 that allows authentication bypass via a crafted POST request. Defenders should prioritize verifying exposure and implementing compensating controls due to the high CVSS score and potential for authentication bypass.

  • Potential authentication bypass, allowing unauthorized access
  • High CVSS score indicating critical severity
  • Verification of exposure and implementation of compensating controls required

Technical summary

The /cas/login component of sso-master v1.0.0 is vulnerable to authentication bypass via a crafted POST request, allowing attackers to authenticate without a password. This vulnerability has a CVSS score of 9.8, indicating critical severity. Defenders should prioritize verifying exposure and implementing compensating controls due to the high CVSS score and potential for authentication bypass. The official CVE Program record and NIST NVD detail page provide additional information on the vulnerability.

Defensive priority

Defenders should prioritize verifying exposure and implementing compensating controls due to the high CVSS score and potential for authentication bypass.

Recommended defensive actions

  • Verify exposure of sso-master v1.0.0 systems to the internet
  • Implement compensating controls, such as multi-factor authentication
  • Monitor for suspicious authentication attempts
  • Review and update incident response plans

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, but additional verification is required to determine the scope of affected systems and remediation steps.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-79577 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-79577

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-79577 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79577

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.