Back to overview

CVE-2026-15630

Description
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

Metadata

CVE ID
CVE-2026-15630
State
PUBLISHED
Assigner
certcc
Reserved
2026-07-13 17:35 UTC
Published
2026-07-23 19:57 UTC
Last updated
2026-07-23 19:57 UTC
Vendor / Product
Casdoor / Casdoor
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Casdoor Casdoor 0 ≤ v3.115.0
Weakness (CWE)
CWESourceDescription
cna CWE-863 Incorrect Authorization
cna CWE-269 Improper Privilege Management
cna CWE-639 Authorization Bypass Through User-Controlled Key
Back to overview