Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without checking the email_verified claim from upstream providers; the idp.UserInfo struct does not even include a EmailVerified field. An attacker can supply an unverified email claim from an upstream provider to take over accounts that use the same email address.
References
| Link | Resource |
|---|---|
| https://kb.cert.org/vuls/id/780781 |
Configurations
No configuration.
History
01 Jun 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
28 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 17:16
Updated : 2026-06-17 11:04
NVD link : CVE-2026-9092
Mitre link : CVE-2026-9092
CVE.ORG link : CVE-2026-9092
JSON object : View
Products Affected
No product.
CWE
No CWE.
