CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-59099

Critical · CVSS 9.1

Apereo CAS — AES-GCM IV/nonce reuse cryptographic vulnerability leading to plaintext recovery (CWE-323)

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-323

Description

Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse across the server lifetime. Attackers can collect multiple client-side webflow execution tokens from the unauthenticated login page and perform known-plaintext analysis to decrypt the webflow conversation state due to keystream reuse caused by a fixed all-zero IV paired with the same encryption key.

Search profile — drives PoC discovery

Symbols AES-GCMinitialization vector reusewebflow execution tokenwebflowExecutionRepositoryall-zero IVkeystream reusewebflow conversation stateCipherExecutorEncodingWebflowConversationRepositoryencodeThumbprint
Keywords CVE-2026-59099Apereo CAS AES-GCM nonce reuseApereo CAS IV reuse plaintext recoveryCAS webflow execution token decryptCAS webflow conversation state cryptographicapereo cas RC6 nonce reuseCAS known-plaintext keystreamgeo-chen cas ossapereo cas 8.0.0-RC6 vulnerabilityCAS unauthenticated login page token collection
Versions: 7.3.0 <= version < 8.0.0-RC6

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T06:30:20.000Z