CVE-2026-79577
Deferred Deferred - Pending Action

Authentication Bypass in sso-master via POST Request

Vulnerability report for CVE-2026-79577, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass flaw in the CAS login system of sso-master v1.0.0. It allows attackers to gain unauthorized administrative access without a password by sending a crafted POST request to /cas/login with specific parameters. The system checks for hardcoded values 'username=admin' and 'system=sso' and grants access unconditionally, bypassing all password validation and security measures.

Detection Guidance

Check for POST requests to /cas/login with parameters username=admin and system=sso. Monitor for successful authentication without password input. Inspect logs for repeated failed login attempts followed by admin access.

Impact Analysis

An attacker could exploit this to log in as an administrator without a password, gaining full control over the application. This could lead to unauthorized data access, modification, or deletion, system compromise, and potential lateral movement within a network. The attack does not require prior knowledge or valid credentials.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements such as GDPR's data protection principles or HIPAA's access controls. Organizations using this software may face legal penalties, reputational damage, and loss of trust due to non-compliance with regulatory standards.

Mitigation Strategies

Update sso-master to a patched version. Remove hardcoded authentication bypass in UsernamePasswordSystemAuthenticationHandler. Disable default admin credentials and enforce strong password policies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79577. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart