CVE Database
/

CVE-2026-9094

Back to search

CVE-2026-9094

Published: May 28, 2026

Modified: Jun 2, 2026

PUBLISHED

Description

Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.

VendorProductVersions

Casdoor

Casdoor

affected
0 - <= 2.362.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now