CVE-2026-59099: Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse across the server lifetime. Attackers can collect multiple client-side webflow execution tokens from the unauthenticated login page and perform known-plaintext analysis to decrypt the webflow conversation state due to keystream reuse caused by a fixed all-zero IV paired with the same encryption key.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apereo CASto a version that resolves this vulnerability.Fixed in 8.0.0-RC6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59099?
CVE-2026-59099 has a critical severity rating of 9.3.
What does CVE-2026-59099 affect?
CVE-2026-59099 affects Apereo CAS versions 7.3.0 before 8.0.0-RC6.
How do I fix CVE-2026-59099?
To fix CVE-2026-59099, upgrade Apereo CAS to version 8.0.0-RC6 or later.
What type of vulnerability is CVE-2026-59099?
CVE-2026-59099 is a cryptographic vulnerability involving AES-GCM nonce reuse.
What can attackers do with CVE-2026-59099?
Attackers can exploit CVE-2026-59099 to recover plaintext conversation state from the server.