SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-79577

CRITICAL · CVSS 9.8 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The /cas/login component of sso-master v1.0.0 is vulnerable to unauthorized access, allowing attackers to authenticate without a password by sending a specially crafted POST request. This flaw poses a significant security risk as it can lead to unauthorized access to sensitive information and functionalities within the application. Organizations using this version of sso-master should prioritize remediation to prevent potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79577
Severity
CRITICAL
CVSS
9.8
EPSS
0.27%

Original NVD Description

An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.