PT-2026-44419 · Casdoor · Casdoor
David Lie
+4
·
Published
2026-05-28
·
Updated
2026-05-28
·
CVE-2026-9090
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Casdoor versions prior to 2.362.1
Description
An authentication bypass exists that allows attackers to impersonate users, bypass multifactor authentication, and gain persistent unauthorized access. The issue occurs because the
buildSpCertificateStore() function extracts the X.509 certificate directly from the incoming SAMLResponse instead of utilizing the trusted pre-configured Identity Provider certificate. This allows an attacker to forge assertions signed with a key under their control. Additionally, flaws in account binding and token exchange mechanisms enable further authentication bypass and privilege escalation.Recommendations
Update to a patched version.
Review authentication logs for suspicious activities related to SAML responses or unexpected account access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Casdoor