Casdoor 2.362.0 and earlier contain an authentication bypass vulnerability in SAML assertion verification. According to the provided content, the vulnerable buildSpCertificateStore function extracts the X.509 signing certificate directly from the incoming SAMLResponse rather than validating the assertion against the trusted, pre-configured Identity Provider certificate. This allows an attacker to supply an arbitrary certificate and corresponding private key, sign forged SAML assertions, and have those assertions accepted as valid by the application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Go proof-of-concept for CVE-2026-9090 affecting Casdoor <= 2.362.0. It contains one executable source file, forge_saml.go, plus README/license and Go module metadata. The exploit is not part of a larger framework. Core capability: forge_saml.go generates a complete SAML 2.0 Response whose Assertion is signed with a newly generated attacker-controlled self-signed RSA certificate. The same certificate is embedded into ds:KeyInfo/X509Certificate inside the signed assertion. The PoC relies on Casdoor's vulnerable behavior of building the signature trust store from the certificate embedded in the incoming SAML response rather than the configured IdP certificate. Because of that, the forged assertion validates against its own attacker-supplied trust anchor. Operational flow in code: main() parses flags for --nameid, --acs, --audience, and --issuer; generates a 2048-bit RSA keypair and self-signed X.509 certificate; constructs a SAML Response and Assertion with Issuer, Subject, NameID, SubjectConfirmationData, Conditions, AudienceRestriction, AuthnStatement, and AttributeStatement fields; signs the Assertion using github.com/russellhaering/goxmldsig with SHA-256 and exclusive canonicalization; inserts the signature into the Assertion; serializes the XML; and outputs a base64-encoded forged SAML response. The NameID and attributes are attacker-controlled and intended to match an existing Casdoor account, including an admin account. The README documents exploitation against Casdoor web endpoints: POST-equivalent submission of the forged SAMLResponse to /api/login with application, organization, provider, and method parameters, targeting the ACS endpoint /api/acs and then validating success via /api/get-account. It also notes that /api/get-application?id=admin/<name> may disclose application/provider configuration useful for targeting. Overall, this is a real exploit PoC for authentication bypass/account impersonation via forged SAML assertions. It does not provide post-exploitation code execution or a shell; its result is unauthorized login/session establishment as an arbitrary existing user on a vulnerable Casdoor deployment.
This repository is a small Python proof-of-concept demonstrating unauthorized Modbus TCP coil writes against a misconfigured PLC/server that treats a supposedly read-only point as writable. The repository contains two code files: modbus_plc_sim.py, which starts a simulated Modbus TCP server on 0.0.0.0:5020 using pymodbus, and exploit_modbus_write.py, which connects to 127.0.0.1:5020 and issues write_coil(0, False). The exploit capability is straightforward: it performs a network-based Modbus write operation to manipulate coil state, with the README framing this as disabling a safety-related output or alarm state. This is not a scanner or detector; it actively changes target state. The code is operational but basic, with a hardcoded localhost target and port, no argument parsing, no authentication handling, and no stealth or automation features. The README claims CVE-2026-9090 and describes the issue as insufficient access control / misconfiguration in a Modbus memory map allowing function code 5 or 15 writes to read-only coils. Overall, the repository’s purpose is educational/demo-oriented: one file simulates the vulnerable service and the other demonstrates exploitation by sending a single unauthorized coil write over Modbus TCP.
This repository is a small, single-script Python proof-of-concept exploit for CVE-2026-9090 affecting Casdoor SAML service-provider certificate validation. The repo contains 3 files: the main exploit script (CVE-2026-9090.py), a short README describing the vulnerability and usage, and requirements.txt listing lxml, signxml, and cryptography. The exploit is not framework-based. Its core capability is SAML authentication forgery: it generates an attacker-controlled RSA keypair and self-signed X.509 certificate, constructs a SAML 2.0 assertion for the user 'admin', signs it with XML-DSig, and relies on the vulnerable Casdoor behavior of trusting the signing certificate embedded in the incoming SAMLResponse instead of validating against the configured IdP certificate. This allows arbitrary assertion signing and impersonation. Operational flow in the script: (1) initialize target base URL from CASDOOR_URL, defaulting to http://127.0.0.1:9350; (2) generate a self-signed certificate; (3) build a forged SAML assertion with issuer https://idp.aerobook.internal/saml/metadata, recipient CASDOOR/api/acs, audience CASDOOR, and admin identity attributes; (4) sign the assertion using signxml with enveloped RSA-SHA256 XML signatures; (5) wrap it in a SAMLResponse; (6) submit it through the ACS/login flow, capture a redirect containing samlResponse, then POST JSON to /api/login with hardcoded provider/application/organization values; and (7) if login succeeds, reuse the authenticated cookie jar to query /api/get-providers?owner=admin as a privilege check / loot step. The exploit is more than a detector and includes a working payload path, but it is still a straightforward PoC/operational script rather than a highly modular weaponized tool. Hardcoded values such as provider='corp-idp', application='app-built-in', organization='built-in', and the forged admin attributes indicate it is tailored to a specific Casdoor SAML configuration or lab environment. The main fingerprintable targets are the Casdoor base URL and API endpoints /api/acs, /api/login, and /api/get-providers?owner=admin, plus the forged issuer URL embedded in the assertion.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.