Executive brief
Casdoor, an open-source identity and access management platform, contains a critical security flaw in how it handles login requests. An attacker can bypass the authentication process by providing a fake security certificate, allowing them to log in as any user, including administrators, without a password. This could lead to a total compromise of the identity system and unauthorized access to all connected applications and customer data.
Technical details
An authentication bypass vulnerability exists in Casdoor's SAML service provider implementation. The 'buildSpCertificateStore' function improperly extracts X.509 certificates directly from incoming SAMLResponse messages rather than validating them against a pre-configured, trusted Identity Provider (IdP) certificate. A remote, unauthenticated attacker can exploit this by crafting a SAML assertion signed with an arbitrary, attacker-controlled key. Successful exploitation allows the attacker to impersonate any user subject within the system. As of the advisory date, no official patch is available.
Affected products
- Casdoor Casdoor <= 2.362.0
Timeline
- 2026-05-28: advisory: Original release date of VU#780781 and GHSA-fwgq-j9r9-qjgr
- 2026-05-28: disclosed: CVE-2026-9090 published