CVE-2026-15630
Description
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Casdoor | Casdoor | — | 0 ≤ v3.115.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-863 Incorrect Authorization |
| — | cna | CWE-269 Improper Privilege Management |
| — | cna | CWE-639 Authorization Bypass Through User-Controlled Key |