# Apereo CAS RCE flaw patched in 7.3.8.3

Published: 2026-09-10 · Severity: routine · Sectors: technology, government-national, education
Canonical: https://vorant.io/reports/a6ea09a4-60db-5a98-a0d6-69e9a5b074ed/apereo-cas-rce-flaw-patched-in-7-3-8-3

> ANSSI advisory warns of a remote code execution vulnerability in Apereo CAS versions before 7.3.8.3.

The French national cybersecurity agency (ANSSI/CERT-FR) published an advisory regarding a vulnerability in Apereo CAS (Central Authentication Service), a widely used open-source single sign-on solution. The flaw affects CAS versions 7.3.x prior to 7.3.8.3 and allows an attacker to achieve remote code execution.

No details on exploitation in the wild are provided in the advisory, and no CVE identifier is referenced in the bulletin text. Defenders running Apereo CAS should consult the vendor's security bulletin published September 8, 2026, and upgrade to version 7.3.8.3 or later to remediate the vulnerability. Given that CAS is often deployed as a central authentication gateway for enterprise and institutional environments, successful exploitation could have significant downstream impact on identity and access management infrastructure.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1150

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a6ea09a4-60db-5a98-a0d6-69e9a5b074ed/apereo-cas-rce-flaw-patched-in-7-3-8-3.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
