{"schema_version":1,"title":"Casbin Casdoor vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 18 vulnerabilities in Casbin Casdoor: 0 in the last 7 days and 4 in the last 90 days, 7 of them critical and 0 exploited in the wild. The most recent, CVE-2026-91998, was published on 15 September 2026.","url":"https://junglewise.ai/threats/technologies/casdoor","json_url":"https://junglewise.ai/threats/technologies/casdoor.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/casdoor","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":18,"critical":7,"exploited":0,"last_7_days":0,"last_30_days":3,"last_90_days":4,"last_365_days":18},"latest":[{"cve":"CVE-2026-91998","cvss":9.9,"epss":0.0059,"slug":"cve-2026-91998-casdoor-authorization-bypass-in-api-mcp-endpoint","title":"Casdoor authorization bypass in /api/mcp endpoint","severity":"critical","exploited":false,"published_at":"2026-09-15T12:17:55.407+00:00","url":"https://junglewise.ai/threats/cve-2026-91998-casdoor-authorization-bypass-in-api-mcp-endpoint"},{"cve":"CVE-2026-90942","cvss":9.6,"epss":0.0028,"slug":"cve-2026-90942-casdoor-certificate-private-key-exposure-in-api-endpoints","title":"Casdoor certificate private key exposure in API endpoints","severity":"critical","exploited":false,"published_at":"2026-09-14T18:20:28.72+00:00","url":"https://junglewise.ai/threats/cve-2026-90942-casdoor-certificate-private-key-exposure-in-api-endpoints"},{"cve":"CVE-2026-84423","cvss":7.3,"epss":0.0069,"slug":"cve-2026-84423-casdoor-missing-authentication-in-upload-resource-api","title":"Casdoor missing authentication in upload-resource API","severity":"high","exploited":false,"published_at":"2026-09-01T23:17:21.497+00:00","url":"https://junglewise.ai/threats/cve-2026-84423-casdoor-missing-authentication-in-upload-resource-api"},{"cve":"CVE-2026-15630","cvss":9.6,"slug":"cve-2026-15630-casdoor-cross-tenant-authorization-bypass-in-multiple-api","title":"Casdoor cross-tenant authorization bypass in multiple API endpoints","severity":"info","exploited":false,"published_at":"2026-07-23T21:17:02.76+00:00","url":"https://junglewise.ai/threats/cve-2026-15630-casdoor-cross-tenant-authorization-bypass-in-multiple-api"},{"cve":"CVE-2026-9098","cvss":9.1,"epss":0.0021,"slug":"cve-2026-9098-casdoor-saml-response-validation-bypass-in-auth-controller","title":"Casdoor SAML response validation bypass in auth controller","severity":"critical","exploited":false,"published_at":"2026-05-28T17:16:34.963+00:00","url":"https://junglewise.ai/threats/cve-2026-9098-casdoor-saml-response-validation-bypass-in-auth-controller"},{"cve":"CVE-2026-9097","cvss":9.8,"epss":0.0048,"slug":"cve-2026-9097-casdoor-missing-jwt-revocation-check-in-token-exchange","title":"Casdoor missing JWT revocation check in token exchange","severity":"critical","exploited":false,"published_at":"2026-05-28T17:16:34.767+00:00","url":"https://junglewise.ai/threats/cve-2026-9097-casdoor-missing-jwt-revocation-check-in-token-exchange"},{"cve":"CVE-2026-9096","cvss":7.5,"epss":0.0043,"slug":"cve-2026-9096-casdoor-saml-assertion-time-bound-enforcement-failure","title":"Casdoor SAML assertion time bound enforcement failure","severity":"high","exploited":false,"published_at":"2026-05-28T17:16:34.647+00:00","url":"https://junglewise.ai/threats/cve-2026-9096-casdoor-saml-assertion-time-bound-enforcement-failure"},{"cve":"CVE-2026-9095","cvss":9.8,"slug":"cve-2026-9095-casdoor-saml-assertion-replay-vulnerability","title":"Casdoor SAML assertion replay vulnerability","severity":"info","exploited":false,"published_at":"2026-05-28T17:16:34.46+00:00","url":"https://junglewise.ai/threats/cve-2026-9095-casdoor-saml-assertion-replay-vulnerability"},{"cve":"CVE-2026-9094","cvss":9.8,"epss":0.0048,"slug":"cve-2026-9094-casdoor-cross-organization-token-exchange-privilege-escalation","title":"Casdoor cross-organization token exchange privilege escalation","severity":"critical","exploited":false,"published_at":"2026-05-28T17:16:34.337+00:00","url":"https://junglewise.ai/threats/cve-2026-9094-casdoor-cross-organization-token-exchange-privilege-escalation"},{"cve":"CVE-2026-9093","cvss":9.8,"epss":0.0048,"slug":"cve-2026-9093-casdoor-saml-audience-restriction-bypass","title":"Casdoor SAML audience restriction bypass","severity":"critical","exploited":false,"published_at":"2026-05-28T17:16:34.21+00:00","url":"https://junglewise.ai/threats/cve-2026-9093-casdoor-saml-audience-restriction-bypass"},{"cve":"CVE-2026-9092","cvss":8.1,"slug":"cve-2026-9092-casdoor-account-takeover-via-unverified-email-binding","title":"Casdoor account takeover via unverified email binding","severity":"info","exploited":false,"published_at":"2026-05-28T17:16:34.083+00:00","url":"https://junglewise.ai/threats/cve-2026-9092-casdoor-account-takeover-via-unverified-email-binding"},{"cve":"CVE-2026-9091","cvss":5.3,"epss":0.0036,"slug":"cve-2026-9091-casdoor-mfa-bypass-in-social-login-binding-flow","title":"Casdoor MFA bypass in social-login binding flow","severity":"medium","exploited":false,"published_at":"2026-05-28T17:16:33.953+00:00","url":"https://junglewise.ai/threats/cve-2026-9091-casdoor-mfa-bypass-in-social-login-binding-flow"},{"cve":"CVE-2026-9090","cvss":9.1,"epss":0.002,"slug":"cve-2026-9090-casdoor-saml-authentication-bypass-via-arbitrary-signing","title":"Casdoor SAML authentication bypass via arbitrary signing certificate","severity":"critical","exploited":false,"published_at":"2026-05-28T17:16:33.82+00:00","url":"https://junglewise.ai/threats/cve-2026-9090-casdoor-saml-authentication-bypass-via-arbitrary-signing"},{"cve":"CVE-2026-6815","cvss":5.9,"epss":0.0059,"slug":"cve-2026-6815-casbin-casdoor-path-traversal-in-local-file-system-storage","title":"Casbin Casdoor path traversal in Local File System storage provider","severity":"medium","exploited":false,"published_at":"2026-05-11T16:17:37.257+00:00","url":"https://junglewise.ai/threats/cve-2026-6815-casbin-casdoor-path-traversal-in-local-file-system-storage"},{"cve":"CVE-2026-5469","cvss":4.7,"epss":0.0057,"slug":"cve-2026-5469-casbin-casdoor-ssrf-in-webhook-url-handler","title":"Casbin Casdoor SSRF in Webhook URL Handler","severity":"medium","exploited":false,"published_at":"2026-04-03T15:16:06.42+00:00","url":"https://junglewise.ai/threats/cve-2026-5469-casbin-casdoor-ssrf-in-webhook-url-handler"},{"cve":"CVE-2026-5468","cvss":3.5,"epss":0.0032,"slug":"cve-2026-5468-casbin-casdoor-cross-site-scripting-in-dangerouslysetinnerhtml","title":"Casbin Casdoor cross site scripting in dangerouslySetInnerHTML","severity":"low","exploited":false,"published_at":"2026-04-03T14:16:33.837+00:00","url":"https://junglewise.ai/threats/cve-2026-5468-casbin-casdoor-cross-site-scripting-in-dangerouslysetinnerhtml"},{"cve":"CVE-2026-5467","cvss":4.3,"epss":0.0043,"slug":"cve-2026-5467-casbin-casdoor-open-redirect-in-oauth-authorization-request","title":"Casbin Casdoor open redirect in OAuth Authorization Request Handler","severity":"medium","exploited":false,"published_at":"2026-04-03T12:16:19.593+00:00","url":"https://junglewise.ai/threats/cve-2026-5467-casbin-casdoor-open-redirect-in-oauth-authorization-request"},{"cve":"CVE-2025-61524","cvss":7.2,"epss":0.0066,"slug":"cve-2025-61524-casdoor-improper-authorization-in-organization-and-application","title":"Casdoor improper authorization in organization and application editing interface","severity":"high","exploited":false,"published_at":"2025-10-08T19:15:44.72+00:00","url":"https://junglewise.ai/threats/cve-2025-61524-casdoor-improper-authorization-in-organization-and-application"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":2,"exploited":0,"vulnerabilities":2},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Casbin Casdoor","slug":"casdoor","vendor":{"name":"Casbin","slug":"casbin","url":"https://junglewise.ai/threats/vendors/casbin"},"aliases":[],"category":"Identity and Access Management (IAM)","homepage":"https://casdoor.org/","repo_url":"https://github.com/casdoor/casdoor","description":"An open-source UI-first Identity Access Management (IAM) / Single-Sign-On (SSO) platform based on Casbin.","url":"https://junglewise.ai/threats/technologies/casdoor"},"most_severe":[{"cve":"CVE-2026-91998","cvss":9.9,"epss":0.0059,"slug":"cve-2026-91998-casdoor-authorization-bypass-in-api-mcp-endpoint","title":"Casdoor authorization bypass in /api/mcp endpoint","severity":"critical","exploited":false,"published_at":"2026-09-15T12:17:55.407+00:00","url":"https://junglewise.ai/threats/cve-2026-91998-casdoor-authorization-bypass-in-api-mcp-endpoint"},{"cve":"CVE-2026-9097","cvss":9.8,"epss":0.0048,"slug":"cve-2026-9097-casdoor-missing-jwt-revocation-check-in-token-exchange","title":"Casdoor missing JWT revocation check in token exchange","severity":"critical","exploited":false,"published_at":"2026-05-28T17:16:34.767+00:00","url":"https://junglewise.ai/threats/cve-2026-9097-casdoor-missing-jwt-revocation-check-in-token-exchange"},{"cve":"CVE-2026-9094","cvss":9.8,"epss":0.0048,"slug":"cve-2026-9094-casdoor-cross-organization-token-exchange-privilege-escalation","title":"Casdoor cross-organization token exchange privilege escalation","severity":"critical","exploited":false,"published_at":"2026-05-28T17:16:34.337+00:00","url":"https://junglewise.ai/threats/cve-2026-9094-casdoor-cross-organization-token-exchange-privilege-escalation"},{"cve":"CVE-2026-9093","cvss":9.8,"epss":0.0048,"slug":"cve-2026-9093-casdoor-saml-audience-restriction-bypass","title":"Casdoor SAML audience restriction bypass","severity":"critical","exploited":false,"published_at":"2026-05-28T17:16:34.21+00:00","url":"https://junglewise.ai/threats/cve-2026-9093-casdoor-saml-audience-restriction-bypass"},{"cve":"CVE-2026-90942","cvss":9.6,"epss":0.0028,"slug":"cve-2026-90942-casdoor-certificate-private-key-exposure-in-api-endpoints","title":"Casdoor certificate private key exposure in API endpoints","severity":"critical","exploited":false,"published_at":"2026-09-14T18:20:28.72+00:00","url":"https://junglewise.ai/threats/cve-2026-90942-casdoor-certificate-private-key-exposure-in-api-endpoints"},{"cve":"CVE-2026-9098","cvss":9.1,"epss":0.0021,"slug":"cve-2026-9098-casdoor-saml-response-validation-bypass-in-auth-controller","title":"Casdoor SAML response validation bypass in auth controller","severity":"critical","exploited":false,"published_at":"2026-05-28T17:16:34.963+00:00","url":"https://junglewise.ai/threats/cve-2026-9098-casdoor-saml-response-validation-bypass-in-auth-controller"},{"cve":"CVE-2026-9090","cvss":9.1,"epss":0.002,"slug":"cve-2026-9090-casdoor-saml-authentication-bypass-via-arbitrary-signing","title":"Casdoor SAML authentication bypass via arbitrary signing certificate","severity":"critical","exploited":false,"published_at":"2026-05-28T17:16:33.82+00:00","url":"https://junglewise.ai/threats/cve-2026-9090-casdoor-saml-authentication-bypass-via-arbitrary-signing"},{"cve":"CVE-2026-9096","cvss":7.5,"epss":0.0043,"slug":"cve-2026-9096-casdoor-saml-assertion-time-bound-enforcement-failure","title":"Casdoor SAML assertion time bound enforcement failure","severity":"high","exploited":false,"published_at":"2026-05-28T17:16:34.647+00:00","url":"https://junglewise.ai/threats/cve-2026-9096-casdoor-saml-assertion-time-bound-enforcement-failure"},{"cve":"CVE-2026-84423","cvss":7.3,"epss":0.0069,"slug":"cve-2026-84423-casdoor-missing-authentication-in-upload-resource-api","title":"Casdoor missing authentication in upload-resource API","severity":"high","exploited":false,"published_at":"2026-09-01T23:17:21.497+00:00","url":"https://junglewise.ai/threats/cve-2026-84423-casdoor-missing-authentication-in-upload-resource-api"},{"cve":"CVE-2025-61524","cvss":7.2,"epss":0.0066,"slug":"cve-2025-61524-casdoor-improper-authorization-in-organization-and-application","title":"Casdoor improper authorization in organization and application editing interface","severity":"high","exploited":false,"published_at":"2025-10-08T19:15:44.72+00:00","url":"https://junglewise.ai/threats/cve-2025-61524-casdoor-improper-authorization-in-organization-and-application"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}