CVE-2026-9094

Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.
References
Configurations

No configuration.

History

02 Jun 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

28 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 17:16

Updated : 2026-06-17 11:04


NVD link : CVE-2026-9094

Mitre link : CVE-2026-9094

CVE.ORG link : CVE-2026-9094


JSON object : View

Products Affected

No product.

CWE

No CWE.