HIGH
Apereo
CVE published 2026-07-24
CVE-2026-15243
Apereo CAS Client vulnerability allows any CA-trusted certificate for hostnames matching configured allowlists or regex, enabling MITM attacks to intercept CAS exchanges and capture Ticket-Granting Tickets (TGTs). Confirmed in versions 4.1.0 (Java Apereo CAS Client) and 3.6.4 (Jasig CAS Client). The issue arises because the client accepts any CA-trusted certificate for any hostname, provided the URL match [truncated]