PT-2026-44419 · Casdoor · Casdoor

David Lie

+4

·

Published

2026-05-28

·

Updated

2026-05-28

·

CVE-2026-9090

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Casdoor versions prior to 2.362.1
Description An authentication bypass exists that allows attackers to impersonate users, bypass multifactor authentication, and gain persistent unauthorized access. The issue occurs because the buildSpCertificateStore() function extracts the X.509 certificate directly from the incoming SAMLResponse instead of utilizing the trusted pre-configured Identity Provider certificate. This allows an attacker to forge assertions signed with a key under their control. Additionally, flaws in account binding and token exchange mechanisms enable further authentication bypass and privilege escalation.
Recommendations Update to a patched version. Review authentication logs for suspicious activities related to SAML responses or unexpected account access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-9090

Affected Products

Casdoor