Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-9098

Quick assessment

Affected
Casdoor Casdoor
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Casdoor是Casdoor开源的一个支持多种身份验证和授权协议的开源平台。 Casdoor 2.362.0及之前版本存在安全漏洞,该漏洞源于controllers/auth.go中的SAML回调处理程序接受发送到/api/acs的任何格式良好的SAMLResponse,而未验证其是否对应于Casdoor先前发出的AuthnRequest,此外,如果管理员在SAML流程开始后禁用或删除身份提供商,处理程序仍使用在请求开始时加载的提供商快照处理响应,控制已注册上游身份提供商的攻击者可以发送未经请求的SAM

AI Predicted 9.1 Difficulty: Easy EPSS 0.23% · P14

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
Casdoor Casdoor ≤ 2.362.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-9098

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CVE-2026-9098
Source: CVE Program / CVE List V5
Vulnerability Description
In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest previously issued by Casdoor. Additionally, if an administrator disables or deletes an IdP (Identity Provider) after a SAML flow has started, the handler still processes the response using the provider snapshot loaded at the start of the request. As a result, an attacker controlling a registered upstream IdP can send unsolicited SAML responses, or replay a legitimately captured response in a different session or after the original flow has ended. In both cases, Casdoor accepts the response and issues a session, enabling persistent unauthorized access.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Casdoor 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Casdoor是Casdoor开源的一个支持多种身份验证和授权协议的开源平台。 Casdoor 2.362.0及之前版本存在安全漏洞,该漏洞源于controllers/auth.go中的SAML回调处理程序接受发送到/api/acs的任何格式良好的SAMLResponse,而未验证其是否对应于Casdoor先前发出的AuthnRequest,此外,如果管理员在SAML流程开始后禁用或删除身份提供商,处理程序仍使用在请求开始时加载的提供商快照处理响应,控制已注册上游身份提供商的攻击者可以发送未经请求的SAM
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Casdoor Casdoor 0 ~ 2.362.0 -

II. Public POCs for CVE-2026-9098

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9098

登录查看更多情报信息。

Vendor Advisories for CVE-2026-9098 (1)

Same Patch Batch · Casdoor · 2026-05-28 · 9 CVEs total

CVE-2026-9091 CVE-2026-9091
CVE-2026-9090 CVE-2026-9090
CVE-2026-9095 CVE-2026-9095
CVE-2026-9093 CVE-2026-9093
CVE-2026-9097 CVE-2026-9097
CVE-2026-9092 CVE-2026-9092
CVE-2026-9094 CVE-2026-9094
CVE-2026-9096 CVE-2026-9096

IV. Related Vulnerabilities

V. Comments for CVE-2026-9098

No comments yet


Leave a comment