VYPR

Central Authentication System (CAS) Server

by Drupal

CVEs (1)

  • CVE-2026-1554MedFeb 4, 2026
    risk 0.27cvss 4.2epss 0.00

    XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2.