PatchSiren

Apereo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Apereo CVE published 2026-07-24

CVE-2026-15243

Apereo CAS Client vulnerability allows any CA-trusted certificate for hostnames matching configured allowlists or regex, enabling MITM attacks to intercept CAS exchanges and capture Ticket-Granting Tickets (TGTs). Confirmed in versions 4.1.0 (Java Apereo CAS Client) and 3.6.4 (Jasig CAS Client). The issue arises because the client accepts any CA-trusted certificate for any hostname, provided the URL match [truncated]