CVE-2026-79577: Sso-master vulnerability
Published Sep 8, 2026
·Updated
An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.
Affected Software
1 affected component
sso-master=1.0.0
Event History
Sep 8, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:18 PM
Description
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs to send a crafted POST request to the /cas/login component. The available information indicates that successful exploitation can authenticate the attacker without a password.
2
Which deployment version is identified as affected?
The issue is reported in sso-master v1.0.0. No other affected or fixed versions are provided.