CVE-2026-5469

A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL Handler. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/submit/781771 Third Party Advisory VDB Entry
https://vuldb.com/vuln/355073 Third Party Advisory VDB Entry
https://vuldb.com/vuln/355073/cti Permissions Required VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:casbin:casdoor:2.356.0:*:*:*:*:*:*:*

History

24 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) Una debilidad ha sido identificada en Casdoor 2.356.0. Esta vulnerabilidad afecta código desconocido del componente Gestor de URL de Webhook. La ejecución de una manipulación puede conducir a falsificación de petición del lado del servidor. El ataque puede ser lanzado remotamente. Se contactó al proveedor con antelación sobre esta divulgación, pero no respondió de ninguna manera.

09 Apr 2026, 00:14

Type Values Removed Values Added
References () https://vuldb.com/submit/781771 - () https://vuldb.com/submit/781771 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/355073 - () https://vuldb.com/vuln/355073 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/355073/cti - () https://vuldb.com/vuln/355073/cti - Permissions Required, VDB Entry
First Time Casbin casdoor
Casbin
CPE cpe:2.3:a:casbin:casdoor:2.356.0:*:*:*:*:*:*:*

03 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 15:16

Updated : 2026-07-24 20:10


NVD link : CVE-2026-5469

Mitre link : CVE-2026-5469

CVE.ORG link : CVE-2026-5469


JSON object : View

Products Affected

casbin

  • casdoor
CWE
CWE-918

Server-Side Request Forgery (SSRF)