Casbin
Casbin Casdoor: vulnerabilidades y CVE
Casbin Casdoor tiene 26 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses17
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-91998 | Crítica (9.4) | 0.59% | — | 15 sept 2026 | Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration… |
| CVE-2026-90942 | Crítica (9.3) | 0.28% | — | 14 sept 2026 | Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the… |
| CVE-2026-84423 | Media (5.5) | 0.69% | — | 1 sept 2026 | A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manipulation leads to missing authentication. It is… |
| CVE-2026-9098 | Crítica (9.1) | 0.21% | — | 28 may 2026 | In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest previously issued… |
| CVE-2026-9097 | Crítica (9.8) | 0.48% | — | 28 may 2026 | Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the JWT signature and parses its claims, but… |
| CVE-2026-9096 | Alta (7.5) | 0.43% | — | 28 may 2026 | Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field.… |
| CVE-2026-9095 | Alta (8.1) | 0.37% | — | 28 may 2026 | Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the result… |
| CVE-2026-9094 | Crítica (9.8) | 0.48% | — | 28 may 2026 | Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the… |
| CVE-2026-9093 | Crítica (9.8) | 0.48% | — | 28 may 2026 | In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on… |
| CVE-2026-9092 | Crítica (9.1) | 0.40% | — | 28 may 2026 | Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without checking the… |
| CVE-2026-9091 | Media (5.3) | 0.36% | — | 28 may 2026 | Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go calls HandleLoggedIn… |
| CVE-2026-9090 | Crítica (9.1) | 0.20% | — | 28 may 2026 | Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts the X.509… |
| CVE-2026-6815 | Media (5.9) | 0.59% | — | 11 may 2026 | An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal… |
| CVE-2026-5469 | Media (5.1) | 0.57% | — | 3 abr 2026 | A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL Handler. Executing a manipulation can lead to server-side request forgery. The attack can be… |
| CVE-2026-5468 | Baja (2) | 0.32% | — | 3 abr 2026 | A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument formCss/formCssMobile/formSideHtml results in cross site scripting.… |
| CVE-2026-5467 | Baja (2.1) | 0.43% | — | 3 abr 2026 | A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request Handler. Such manipulation of the argument redirect_uri leads to open… |
| CVE-2025-61524 | Alta (7.2) | 0.66% | — | 8 oct 2025 | An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within… |
| CVE-2025-4210 | Media (6.9) | 1.8% | — | 2 may 2025 | A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function HandleScim of the file controllers/scim.go of the component SCIM User Creation Endpoint. The… |
| CVE-2024-41658 | Media (6.1) | 0.45% | — | 20 ago 2024 | Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, he purchase URL that is created to generate a WechatPay QR code is vulnerable to reflected XSS.… |
| CVE-2024-41657 | Alta (8.8) | 0.79% | — | 20 ago 2024 | Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make… |
| CVE-2024-41264 | Alta (7.5) | 0.46% | — | 1 ago 2024 | An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method. |
| CVE-2024-5587 | Media (6.9) | 0.47% | — | 2 jun 2024 | A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown function of the file /conf/app.conf of the component Configuration File Handler. The manipulation leads… |
| CVE-2023-34927 | Media (6.5) | 3.1% | — | 22 jun 2023 | Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via… |
| CVE-2022-44942 | Alta (8.1) | 0.87% | — | 7 dic 2022 | Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function. |
| CVE-2022-38638 | Crítica (9.1) | 1.2% | — | 9 sept 2022 | Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource. |
| CVE-2022-24124 | Alta (7.5) | 55% | — | 29 ene 2022 | The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.