{"id":"CVE-2026-90942","title":"Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it","summary":"Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key…","severity":"critical","cvss":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","cwe":["CWE-863"],"vendor":"casdoor","product":"casdoor","affected":["casdoor <= 4.4.0"],"published":"2026-09-14","updated":"2026-09-23","sourceUpdated":"2026-09-23T17:17:44.670","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90942","references":[{"url":"https://github.com/casdoor/casdoor","label":"disclosure@vulncheck.com"},{"url":"https://github.com/casdoor/casdoor/blob/v4.4.0/controllers/cert.go","label":"disclosure@vulncheck.com"},{"url":"https://github.com/casdoor/casdoor/blob/v4.4.0/object/cert.go","label":"disclosure@vulncheck.com"},{"url":"https://github.com/geo-chen/oss/blob/main/casdoor.md#finding-3-organization-admin-can-read-the-global-built-in-jwt-signing-private-key-via-apiget-certs-and-apiget-cert-incomplete-fix-of-3003--enables-cross-organization-token-forgery","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/casdoor-through-4.4.0-private-key-exposure-via-certificate-endpoints","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00277,"epssPercentile":0.17987,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-14T19:07:44.583769Z"},"ingestedAt":"2026-09-14T19:13:23.462Z","slug":"CVE-2026-90942","body":"## Overview\n\nCasdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":65,"depthScoreParts":{"impact":52.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":203277,"id":"CVE-2026-90942","ts":1789416905263,"field":"exploit_available","old":"false","new":"true"}]}