CVE-2026-9094 Details
Description
Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.
A vulnerability in Casdoor versions through 2.362.0 allows cross-organization token exchange, leading to privilege escalation. The issue arises in the GetTokenExchangeToken function, which validates JWT signatures but fails to ensure that the token's user is from the same organization as the target application. This oversight can result in unauthorized access across different organizations.
Users are advised to implement stricter identity governance controls, restrict the use of identity providers to trusted sources, and monitor logs for unusual SAML or token activity. High-privilege accounts should be reinforced with additional authentication measures, such as multi-factor authentication.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 28, 2026CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.cert.org/vuls/id/780781 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Casdoor | <= 2.362.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | New CVE Received | [email protected] |
Volerion