In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor.
References
| Link | Resource |
|---|---|
| https://kb.cert.org/vuls/id/780781 |
Configurations
No configuration.
History
02 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
28 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 17:16
Updated : 2026-06-17 11:04
NVD link : CVE-2026-9093
Mitre link : CVE-2026-9093
CVE.ORG link : CVE-2026-9093
JSON object : View
Products Affected
No product.
CWE
No CWE.
