Casdoor does not validate the AudienceRestriction element in SAML assertions (CVE-2026-9093)
In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor.
AI Analysis
Technical Summary
The vulnerability in Casdoor (<=2.362.0) involves improper validation of the AudienceRestriction element in SAML assertions. Specifically, the buildSp function in object/saml_sp.go fails to set the AudienceURI on the gosaml2 SAMLServiceProvider struct and does not inspect the WarningInfo.NotInAudience field. As a result, Casdoor accepts assertions issued for different service providers, violating the intended audience restriction and allowing potential unauthorized authentication.
Potential Impact
Successful exploitation allows an attacker to use SAML assertions issued for other service providers to authenticate to Casdoor, potentially leading to unauthorized access with full confidentiality, integrity, and availability impact as indicated by the CVSS vector (C:H/I:H/A:H). This can compromise user accounts and system resources protected by Casdoor's SAML authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider disabling SAML authentication or implementing additional validation controls externally to ensure AudienceRestriction is enforced.
Casdoor does not validate the AudienceRestriction element in SAML assertions (CVE-2026-9093)
Description
In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor.
CVSS v3.1
Score 9.8critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Casdoor (<=2.362.0) involves improper validation of the AudienceRestriction element in SAML assertions. Specifically, the buildSp function in object/saml_sp.go fails to set the AudienceURI on the gosaml2 SAMLServiceProvider struct and does not inspect the WarningInfo.NotInAudience field. As a result, Casdoor accepts assertions issued for different service providers, violating the intended audience restriction and allowing potential unauthorized authentication.
Potential Impact
Successful exploitation allows an attacker to use SAML assertions issued for other service providers to authenticate to Casdoor, potentially leading to unauthorized access with full confidentiality, integrity, and availability impact as indicated by the CVSS vector (C:H/I:H/A:H). This can compromise user accounts and system resources protected by Casdoor's SAML authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider disabling SAML authentication or implementing additional validation controls externally to ensure AudienceRestriction is enforced.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-3w4h-g9f5-j84p
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-9093"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a46ecbe27e9c7971943d0c2
Added to database: 07/02/2026, 22:57:02 UTC
Last enriched: 07/02/2026, 23:15:45 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.