CVE-2026-9094Critical· 9.8▾ MidnightCasdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.
github.com/casdoor/casdoor < 2.387.0Upgrade to a patched release:
github.com/casdoor/casdoor 2.387.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6815Medium· 5.9Casdoor: Arbitrary file write possible through Local File System storage provider
CVE-2026-91998Critical· 9.9Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizati…
CVE-2026-90942Critical· 9.6Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it
CVE-2026-15630Critical· 9.9CVE-2026-15630