Junglewise Threat Intelligence

CVE-2026-79577: sso-master /cas/login authentication bypass

CVE-2026-79577 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Executive brief

sso-master is an authentication server that manages login sessions for applications. An attacker can bypass password verification and gain admin access to the system by sending a specially crafted login request to the /cas/login endpoint, allowing unauthorized administrative access without needing any password or account credentials.

Technical details

The vulnerability exists in the UsernamePasswordSystemAuthenticationHandler authentication handler (order=1), which contains a hardcoded success branch in its doAuthentication() method. When the username equals "admin" and the system parameter equals "sso", authentication succeeds unconditionally without verifying the password field. An attacker can POST to /cas/login with username=admin, system=sso, and any password value to receive a valid admin TGT (Ticket Granting Ticket) and SSO session. No prerequisites such as captcha, account existence, or password knowledge are required. The vulnerability affects sso-master v1.0.0 and has been confirmed as reproducible on affected versions.

Affected products

  • sso-master sso-master v1.0.0

Timeline

  • 2026-09-08: disclosed: CVE-2026-79577 published on NVD
  • 2026-08-24: exploited: Live reproduction confirmed on affected version

References