PT-2026-44423 · Casdoor · Casdoor
David Lie
+4
·
Published
2026-05-28
·
Updated
2026-05-29
·
CVE-2026-9094
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Casdoor versions prior to 2.362.1
Description
An issue allows cross-organization token exchange. The
GetTokenExchangeToken() function in object/token oauth.go validates JWT signatures but fails to verify if the token's user belongs to the same organization as the target application, potentially leading to privilege escalation across organizational boundaries.Recommendations
Update to a version later than 2.362.0.
As a temporary workaround, restrict access to the
GetTokenExchangeToken() function until the update is applied.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Casdoor