PT-2026-44421 · Casdoor · Casdoor

·

CVE-2026-9092

·

Published

2026-05-28

·

Updated

2026-05-28

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Casdoor versions prior to 2.363.0
Description An issue exists involving unverified email binding that may enable account takeover. The getExistUserByBindingRule() function matches users by email without verifying the email verified claim from upstream providers, as the idp.UserInfo struct lacks an EmailVerified field. An attacker can provide an unverified email claim from an upstream provider to take over accounts associated with the same email address.
Recommendations Update to a version later than 2.362.0.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-9092

Affected Products

Casdoor