Back to overview

CVE-2026-9093

CRITICAL
9.8
CVSS 3.1
Description
In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor.

Metadata

CVE ID
CVE-2026-9093
State
PUBLISHED
Assigner
certcc
Reserved
2026-05-20 15:04 UTC
Published
2026-05-28 16:21 UTC
Last updated
2026-06-02 16:44 UTC
Vendor / Product
Casdoor / Casdoor
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Casdoor Casdoor 0 ≤ 2.362.0
Weakness (CWE)
CWESourceDescription
cna CWE-863 Incorrect Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview