VORANT. Threat Intelligence Sign in Get the full feed

Apereo CAS Client MITM cert flaw disclosed

medium vulnerability

Apereo/Jasig CAS Client accepts any CA-trusted certificate for allowlisted hostnames, letting a MITM attacker steal CAS tickets and impersonate users.

CERT Polska coordinated disclosure of CVE-2026-15243, a certificate-validation flaw in the Apereo CAS Client (and its predecessor Jasig CAS Client) used to implement Single Sign-On authentication. The client validates only that a presented TLS certificate is signed by a trusted CA and that the requested URL matches a configured allowlist or regex, without verifying that the certificate actually belongs to the expected hostname. An attacker positioned to intercept traffic — via DNS poisoning, a rogue Wi-Fi access point, or a malicious proxy — can present any valid CA-signed certificate for an allowlisted-matching hostname to intercept the CAS authentication exchange.

Successful exploitation allows the attacker to capture a victim's Ticket-Granting Ticket (TGT) and subsequently mint Service Tickets on the victim's behalf, effectively hijacking SSO sessions across services relying on the compromised CAS instance. The issue has been confirmed in Java Apereo CAS Client 4.1.0 and Jasig CAS Client 3.6.4, though other versions may be affected. CERT Polska notes that attempts to contact the maintainers were unsuccessful, so no official patch is currently confirmed, leaving organizations reliant on unpatched or unmaintained CAS client implementations exposed until remediation or mitigating controls (such as enforced hostname verification or network-layer TLS protections) are applied.

Mentioned in this report

Vulnerabilities CVE-2026-15243

Source reporting: https://cert.pl/en/posts/2026/07/CVE-2026-15243

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free