What is CVE-2026-15243?
CVE-2026-15243 is in Apereo CAS Client. The client improperly accepts any CA-trusted certificate for a hostname as long as the URL matches the configured allowlist/regex. This allows an attacker in a MITM position to present a fraudulent certificate.
Azərbaycanca: CVE-2026-15243 Apereo CAS Client üçün müəyyən edilib. Bu boşluq zamanı müştəri, URL təsdiq siyahısına uyğun olduğu müddətcə, hər hansı host adı üçün istənilən CA tərəfindən imzalanmış sertifikatı qəbul edir. Bu, MITM mövqeyində olan şəxsə saxta sertifikat təqdim etməyə imkan verir.
Related CVEs
link basis: same weakness class CWE-287
FAQ1
What kind of threat does CVE-2026-15243 pose in Apereo CAS Client?
Since the client accepts any CA-trusted certificate for a hostname, an attacker in a MITM position can present a fraudulent certificate.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.