PatchSiren cyber security CVE debrief
CVE-2026-79577 fangtang7 CVE debrief
A critical vulnerability in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request. This issue has a CVSS score of 9.8 and is considered CRITICAL. Defenders responsible for sso-master v1.0.0 systems, particularly those exposed to the internet, should assess their exposure and implement compensating controls. The CVE record and NVD detail page provide information on the vulnerability, but additional verification is required to determine the scope of affected systems and remediation steps.
- Vendor
- fangtang7
- Product
- sso-master
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-08
- Original CVE updated
- 2026-09-14
- Advisory published
- 2026-09-08
- Advisory updated
- 2026-09-14
Who should care
Defenders responsible for sso-master v1.0.0 systems, particularly those exposed to the internet, should assess their exposure and implement compensating controls.
Why it matters
CVE-2026-79577 is a critical vulnerability in sso-master v1.0.0 that allows authentication bypass via a crafted POST request. Defenders should prioritize verifying exposure and implementing compensating controls due to the high CVSS score and potential for authentication bypass.
- Potential authentication bypass, allowing unauthorized access
- High CVSS score indicating critical severity
- Verification of exposure and implementation of compensating controls required
Technical summary
The /cas/login component of sso-master v1.0.0 is vulnerable to authentication bypass via a crafted POST request, allowing attackers to authenticate without a password. This vulnerability has a CVSS score of 9.8, indicating critical severity. Defenders should prioritize verifying exposure and implementing compensating controls due to the high CVSS score and potential for authentication bypass. The official CVE Program record and NIST NVD detail page provide additional information on the vulnerability.
Defensive priority
Defenders should prioritize verifying exposure and implementing compensating controls due to the high CVSS score and potential for authentication bypass.
Recommended defensive actions
- Verify exposure of sso-master v1.0.0 systems to the internet
- Implement compensating controls, such as multi-factor authentication
- Monitor for suspicious authentication attempts
- Review and update incident response plans
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, but additional verification is required to determine the scope of affected systems and remediation steps.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-79577 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-79577
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-79577 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79577
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/fangtang7/CVE/blob/main/sso-master/sso.md
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.