Junglewise Threat Intelligence

CVE-2026-90942: Casdoor certificate private key exposure in API endpoints

CVE-2026-90942 · Severity: critical · CVSS 9.6 · Published 2026-09-14

Technologies: Casdoor.

Executive brief

Casdoor is an open-source identity and access management (IAM) platform used to manage user authentication and authorization. The vulnerability allows organization administrators to retrieve the instance-wide certificate private key through API endpoints, which can be weaponized to forge authentication tokens and impersonate any user, including global administrators, compromising the entire authentication system.

Technical details

Casdoor through version 4.4.0 fails to properly mask the instance-wide built-in certificate private key when returning certificate data from the /api/get-certs and /api/get-cert endpoints. The vulnerability is a broken access control issue affecting the certificate management API. An authenticated organization administrator can make requests to these endpoints to extract the private key without authorization. With the exposed private key, an attacker can forge JWT tokens for any user in any organization, including global administrators, completely bypassing authentication mechanisms. Patches addressing this insufficient output encoding are expected in versions after 4.4.0.

Affected products

  • Casdoor Casdoor through 4.4.0

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: advisory: CVE-2026-90942

References