VORANT. Threat Intelligence Sign in Get the full feed

Casdoor IAM platform ≤2.362.0 contains nine critical authentication bypass…

critical vulnerability

Casdoor IAM platform ≤2.362.0 contains nine critical authentication bypass vulnerabilities enabling SAML assertion forgery, MFA bypass, and cross-organization privilege escalation.

Casdoor, an open-source identity and access management platform, suffers from multiple critical vulnerabilities across its SAML processing, account binding, and token exchange mechanisms. The most severe flaws allow attackers to forge SAML assertions using arbitrary certificates, replay captured assertions without detection, and bypass multifactor authentication through social login flows. Additional vulnerabilities enable account takeover via unverified email claims, cross-organization token exchange without membership validation, and the processing of expired or unsolicited SAML responses.

These vulnerabilities collectively undermine Casdoor's authentication architecture. Attackers can impersonate arbitrary users including administrators, maintain persistent unauthorized access, and escalate privileges across organizational boundaries. The platform fails to enforce fundamental security controls including certificate trust validation, assertion replay protection, time-bound enforcement, audience restriction checking, and token revocation verification.

No patch is currently available as CERT/CC was unable to coordinate disclosure with the Casdoor development team. Organizations running affected versions should implement compensating controls including restricting IdP usage to trusted providers only, enforcing downstream MFA for high-privilege accounts, and monitoring authentication logs for anomalous SAML and token activity.

Mentioned in this report

Vulnerabilities CVE-2026-9090CVE-2026-9091CVE-2026-9092CVE-2026-9093CVE-2026-9094CVE-2026-9095CVE-2026-9096CVE-2026-9097CVE-2026-9098

Source reporting: https://kb.cert.org/vuls/id/780781

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free