Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2026-9098

AI Predicted 9.1 Difficulty: Easy EPSS 0.01% · P1

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProductVersion RangeStatus
CasdoorCasdoor≤ 2.362.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-9098

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CVE-2026-9098
Source: NVD (National Vulnerability Database)
Vulnerability Description
In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest previously issued by Casdoor. Additionally, if an administrator disables or deletes an IdP (Identity Provider) after a SAML flow has started, the handler still processes the response using the provider snapshot loaded at the start of the request. As a result, an attacker controlling a registered upstream IdP can send unsolicited SAML responses, or replay a legitimately captured response in a different session or after the original flow has ended. In both cases, Casdoor accepts the response and issues a session, enabling persistent unauthorized access.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Casdoor 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Casdoor是Casdoor开源的一个支持多种身份验证和授权协议的开源平台。 Casdoor 2.362.0及之前版本存在安全漏洞,该漏洞源于controllers/auth.go中的SAML回调处理程序接受发送到/api/acs的任何格式良好的SAMLResponse,而未验证其是否对应于Casdoor先前发出的AuthnRequest,此外,如果管理员在SAML流程开始后禁用或删除身份提供商,处理程序仍使用在请求开始时加载的提供商快照处理响应,控制已注册上游身份提供商的攻击者可以发送未经请求的SAM
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CasdoorCasdoor 0 ~ 2.362.0 -

II. Public POCs for CVE-2026-9098

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9098

登录查看更多情报信息。

Vendor Advisories for CVE-2026-9098 (1)

Same Patch Batch · Casdoor · 2026-05-28 · 9 CVEs total

CVE-2026-9091CVE-2026-9091
CVE-2026-9090CVE-2026-9090
CVE-2026-9095CVE-2026-9095
CVE-2026-9093CVE-2026-9093
CVE-2026-9097CVE-2026-9097
CVE-2026-9092CVE-2026-9092
CVE-2026-9094CVE-2026-9094
CVE-2026-9096CVE-2026-9096

IV. Related Vulnerabilities

V. Comments for CVE-2026-9098

No comments yet


Leave a comment