CVE Database
/

CVE-2026-9092

Back to search

CVE-2026-9092

Published: May 28, 2026

Modified: Jun 1, 2026

PUBLISHED

Description

Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without checking the email_verified claim from upstream providers; the idp.UserInfo struct does not even include a EmailVerified field. An attacker can supply an unverified email claim from an upstream provider to take over accounts that use the same email address.

VendorProductVersions

Casdoor

Casdoor

affected
0 - <= 2.362.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now