Executive brief
Casdoor is an open-source identity and access management (IAM) platform used to manage user authentication and authorization. The vulnerability allows organization administrators to retrieve the instance-wide certificate private key through API endpoints, which can be weaponized to forge authentication tokens and impersonate any user, including global administrators, compromising the entire authentication system.
Technical details
Casdoor through version 4.4.0 fails to properly mask the instance-wide built-in certificate private key when returning certificate data from the /api/get-certs and /api/get-cert endpoints. The vulnerability is a broken access control issue affecting the certificate management API. An authenticated organization administrator can make requests to these endpoints to extract the private key without authorization. With the exposed private key, an attacker can forge JWT tokens for any user in any organization, including global administrators, completely bypassing authentication mechanisms. Patches addressing this insufficient output encoding are expected in versions after 4.4.0.
Affected products
- Casdoor Casdoor through 4.4.0
Timeline
- 2026-09-14: disclosed
- 2026-09-14: advisory: CVE-2026-90942