CVE-2026-6815

An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the application's intended storage sandbox.
References
Link Resource
https://kb.cert.org/vuls/id/937808 Third Party Advisory VDB Entry
https://www.kb.cert.org/vuls/id/937808 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:casbin:casdoor:*:*:*:*:*:*:*:*

History

01 Jun 2026, 16:38

Type Values Removed Values Added
References () https://kb.cert.org/vuls/id/937808 - () https://kb.cert.org/vuls/id/937808 - Third Party Advisory, VDB Entry
References () https://www.kb.cert.org/vuls/id/937808 - () https://www.kb.cert.org/vuls/id/937808 - Third Party Advisory, VDB Entry
First Time Casbin casdoor
Casbin
CWE CWE-22
CPE cpe:2.3:a:casbin:casdoor:*:*:*:*:*:*:*:*

13 May 2026, 14:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9

11 May 2026, 18:16

Type Values Removed Values Added
References
  • () https://www.kb.cert.org/vuls/id/937808 -

11 May 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 16:17

Updated : 2026-06-01 16:38


NVD link : CVE-2026-6815

Mitre link : CVE-2026-6815

CVE.ORG link : CVE-2026-6815


JSON object : View

Products Affected

casbin

  • casdoor
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')