Feed/CVE-2026-9094
CVE-2026-9094CRITICALCVSS 9.8

Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check

Published May 28, 2026·Updated Jul 9, 2026

NVD Description

Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.

Affected Packages (1)

github.com/casdoor/casdoorGO
Fixed in 2.387.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free