CVE-2026-15630

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
Configurations

No configuration.

History

27 Jul 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.9
CWE CWE-639
CWE-269
CWE-863
References () https://vokecyber.com/research/cve-2026-15630-casdoor-cross-tenant-authz - () https://vokecyber.com/research/cve-2026-15630-casdoor-cross-tenant-authz -

23 Jul 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-23 21:17

Updated : 2026-07-30 19:10


NVD link : CVE-2026-15630

Mitre link : CVE-2026-15630

CVE.ORG link : CVE-2026-15630


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management

CWE-639

Authorization Bypass Through User-Controlled Key

CWE-863

Incorrect Authorization