Junglewise Threat Intelligence

CVE-2026-9093: Casdoor SAML audience restriction bypass

CVE-2026-9093 · Severity: critical · CVSS 9.8 · Published 2026-05-28

Technologies: Casdoor, github.com/casdoor/casdoor (Go). Vendors: Go.

Executive brief

Casdoor, an open-source identity and access management platform, fails to properly verify the intended recipient of security tokens (SAML assertions). This flaw allows an attacker to take a security token intended for a different service and reuse it to gain unauthorized access to Casdoor. Successful exploitation could lead to full account takeover, including administrative accounts, and unauthorized access to sensitive corporate data.

Technical details

A vulnerability exists in Casdoor's SAML service provider implementation due to missing validation of the AudienceRestriction element. The 'buildSp' function in 'object/saml_sp.go' fails to set the 'AudienceURI' on the 'gosaml2.SAMLServiceProvider' struct and does not inspect 'WarningInfo.NotInAudience'. Consequently, Casdoor will accept SAML assertions issued by an Identity Provider (IdP) for entirely different service providers. An unauthenticated remote attacker can exploit this to achieve authentication bypass by presenting a valid assertion intended for another application. As of the advisory date, no patch is available.

Affected products

  • Casdoor Casdoor <= 2.362.0

Timeline

  • 2026-05-28: advisory: Initial disclosure by CERT/CC and GitHub Advisory Database
  • 2026-05-28: disclosed

References

Related threats