CERT/CC and independent researchers disclosed multiple critical vulnerabilities in the open-source identity and access management platform Casdoor, affecting version 2.362.0 and earlier. The most severe issue, CVE-2026-9090, stems from improper SAML certificate validation that can let an attacker forge assertions using a self-controlled certificate and log in without valid credentials. Additional flaws, including CVE-2026-9091, can allow multi-factor authentication bypass and exploitation of weak account-binding logic, while CVE-2026-9094 and CVE-2026-9097 create risks of cross-organization token abuse and privilege escalation.
The disclosures warn that the vulnerabilities undermine core authentication and access-management controls in deployments using Casdoor for identity federation and tenant separation. Researchers said no official patch was available at disclosure because they were unable to coordinate with the Casdoor team, and advised defenders to apply manual mitigations such as restricting identity provider integrations, tightening identity governance, enforcing downstream MFA protections, and monitoring for anomalous SAML responses and token-exchange activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers disclosed multiple critical vulnerabilities in Casdoor affecting version 2.362.0 and earlier, including CVE-2026-9090, CVE-2026-9091, CVE-2026-9094, and CVE-2026-9097. The disclosure states that no official patch was available at the time because researchers were unable to coordinate with the Casdoor team, and recommends manual mitigations.
CERT/CC published VU#780781 describing multiple authentication bypass and access management vulnerabilities in Casdoor. The advisory identifies the issue set as affecting the product and serves as the public disclosure point in the provided references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.