Casdoor has an authentication bypass (CVE-2026-9090)
Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts the X.509 certificate directly from the incoming SAMLResponse instead of using the trusted pre-configured Identity Provider certificate, allowing an attacker to forge assertions signed with an attacker-controlled key.
AI Analysis
Technical Summary
The vulnerability in Casdoor (CVE-2026-9090) affects versions 2.362.0 and earlier. It allows an attacker to bypass authentication by exploiting improper certificate validation in the SAMLResponse processing. Specifically, the buildSpCertificateStore function does not validate the signing certificate against a trusted Identity Provider certificate but instead uses the certificate extracted directly from the SAMLResponse. This enables attackers to forge signed assertions using their own keys, effectively bypassing authentication controls.
Potential Impact
Successful exploitation leads to a complete authentication bypass, allowing attackers to impersonate any user without valid credentials. This compromises confidentiality and integrity of the authentication process, potentially granting unauthorized access to protected resources. Availability is not impacted.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid deploying vulnerable versions in sensitive environments or implement additional controls to validate SAMLResponse certificates against trusted Identity Provider certificates.
Casdoor has an authentication bypass (CVE-2026-9090)
Description
Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts the X.509 certificate directly from the incoming SAMLResponse instead of using the trusted pre-configured Identity Provider certificate, allowing an attacker to forge assertions signed with an attacker-controlled key.
CVSS v3.1
Score 9.1critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Casdoor (CVE-2026-9090) affects versions 2.362.0 and earlier. It allows an attacker to bypass authentication by exploiting improper certificate validation in the SAMLResponse processing. Specifically, the buildSpCertificateStore function does not validate the signing certificate against a trusted Identity Provider certificate but instead uses the certificate extracted directly from the SAMLResponse. This enables attackers to forge signed assertions using their own keys, effectively bypassing authentication controls.
Potential Impact
Successful exploitation leads to a complete authentication bypass, allowing attackers to impersonate any user without valid credentials. This compromises confidentiality and integrity of the authentication process, potentially granting unauthorized access to protected resources. Availability is not impacted.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid deploying vulnerable versions in sensitive environments or implement additional controls to validate SAMLResponse certificates against trusted Identity Provider certificates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-fwgq-j9r9-qjgr
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-9090"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a46ecbe27e9c7971943d0c7
Added to database: 07/02/2026, 22:57:02 UTC
Last enriched: 07/02/2026, 23:15:49 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.