{"id":"CVE-2026-15630","title":"CVE-2026-15630","summary":"A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).","severity":"critical","cvss":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cvssSource":"adp","cwe":["CWE-863","CWE-269","CWE-639"],"vendor":"Casdoor","product":"Casdoor","affected":["Casdoor < v4.3.0"],"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-07-27T16:29:47.895568Z"},"exploitAvailable":true,"published":"2026-07-23","updated":"2026-09-11","sourceUpdated":"2026-09-11T18:33:14.618Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-15630","references":[{"url":"https://vokecyber.com/research/cve-2026-15630-casdoor-cross-tenant-authz"}],"tags":["cve.org","exploit-available"],"epss":0.00342,"epssPercentile":0.2767,"ingestedAt":"2026-09-14T00:35:28.535Z","slug":"CVE-2026-15630","body":"## Overview\n\nA non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).\n\n## Affected\n\n- `Casdoor < v4.3.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":67,"depthScoreParts":{"impact":54.5,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}