CVE Database
/

CVE-2026-9093

Back to search

CVE-2026-9093

Published: May 28, 2026

Modified: Jun 2, 2026

PUBLISHED

Description

In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor.

VendorProductVersions

Casdoor

Casdoor

affected
0 - <= 2.362.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now