A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
References
Configurations
No configuration.
History
27 Jul 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.9 |
| CWE | CWE-639 CWE-269 CWE-863 |
|
| References | () https://vokecyber.com/research/cve-2026-15630-casdoor-cross-tenant-authz - |
23 Jul 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-23 21:17
Updated : 2026-07-30 19:10
NVD link : CVE-2026-15630
Mitre link : CVE-2026-15630
CVE.ORG link : CVE-2026-15630
JSON object : View
Products Affected
No product.
