CVE-2026-79577Critical· 9.8▾ AbyssalPoC availableAn issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
Exploit / PoC code exists
— → 9.8
none → critical
9.8 → —
critical → none
— → 9.8
none → critical
0.1% → 0.3%
An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-10072Medium· 6.3A vulnerability was found in Portabilis i-Educar up to 2.10
CVE-2026-43760High· 8.6An access issue was addressed with improved access restrictions
CVE-2026-12261Medium· 6.5A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning
CVE-2025-70962High· 7.5Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control
CVE-2026-47301High· 8.8Configuration Manager Elevation of Privilege Vulnerability
CVE-2026-1609High· 8.1A flaw was found in Keycloak