CTIPilot
← Back to the live brief
HIGHNATOA2vulnerability

Apereo CAS: an embargoed remote-code-execution disclosure affects every 7.3.x deployment regardless of configuration, patched to 7.3.8.3, no CVE or technical detail published yet

Apereo's own advisory: "you are affected if you simply run CAS", patch now, technical detail is still under embargo

Defender actions

  • Upgrade every Apereo CAS 7.3.x deployment to the patched 7.3.8.3 release now, without waiting for the technical write-up Apereo says will follow once the grace window passes; the vendor states the issue affects any standard deployment regardless of feature use, customization or theme.

Analysis

Apereo, the open-source project behind CAS (Central Authentication Service) (a widely deployed SSO/identity-provider server used across higher education and, per CERT-FR's advisory the same day, flagged to the French government constituency) disclosed a vulnerability on 2026-09-08 under its formal grace-window vulnerability-response process, which withholds technical detail for a period after the fix ships (Apereo Community Blog, 2026-09-08). What Apereo does state: the issue is not tied to any specific feature, extension, customized UI or theme, and "you are affected if you simply run CAS"; exploitation "will lead to remote code execution attempts" (Apereo Community Blog, 2026-09-08). The affected release line is 7.3.x. A third party, working anonymously and describing its analysis as "almost entirely driven by AI," reported the issue on 2026-09-04, and Apereo's security team validated, tested and shipped the fix as CAS 7.3.8.3 on 2026-09-08, described as a drop-in replacement for standard deployments (Apereo Community Blog, 2026-09-08). No CVE identifier or CVSS score has been published as of this writing, an unusual gap for an RCE-class disclosure. CERT-FR (ANSSI) independently carried the advisory the same window, rating the risk "arbitrary remote code execution" (translated from French) (CERT-FR, 2026-09-10).

Because Apereo's own language deliberately omits the vulnerable component, the authentication precondition and the trigger mechanism during the embargo window, this is patch-now guidance rather than a hunt-and-detect brief: organizations running CAS 7.3.x should upgrade to the fixed 7.3.8.3 release without waiting for the technical write-up Apereo says will follow once the grace window passes.

Cited evidence

The issue addressed here is not tied or connected to a specific feature or extension of the CAS software, and ultimately will lead to remote code execution attempts. While the affected area largely has to do with UI, the specific nature of the issue has nothing to do with whether the CAS deployment has customized the user interface or runs with a custom theme.

You are affected if you simply run CAS.

The issues were originally reported to the CAS project on September 4th, 2026 and fixed on September 8th, 2026.

The issues (almost entirely driven by AI analysis) were reported to the CAS project by third-party researchers (who decided to remain anonymous) and were then further validated and tested by the CAS security team.

Apereo Community Blog (CAS project) 2026-09-08

A vulnerability has been discovered in Apereo CAS. It allows an attacker to cause arbitrary remote code execution. (translated from French)

CERT-FR / ANSSI

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.