CVE-2025-61524: n/a
An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login
AI Analysis
Technical Summary
This vulnerability in Casdoor (<=2.26.0) involves a flaw in the permission verification module and the organization/application editing interface. Remote authenticated administrators can bypass the system's permission checks by directly concatenating URLs after login, effectively escalating their privileges beyond intended limits. The issue is resolved in version 2.63.0.
Potential Impact
An attacker with authenticated administrator access to any organization within the Casdoor system can bypass permission verification controls, potentially leading to unauthorized access and full compromise of confidentiality, integrity, and availability of the system. The CVSS score of 7.2 (high) reflects the network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade Casdoor to version 2.63.0 or later, where this vulnerability is fixed. No other mitigation or temporary workaround is indicated in the available data.
CVE-2025-61524: n/a
Description
An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login
CVSS v3.1
Score 7.2high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Casdoor (<=2.26.0) involves a flaw in the permission verification module and the organization/application editing interface. Remote authenticated administrators can bypass the system's permission checks by directly concatenating URLs after login, effectively escalating their privileges beyond intended limits. The issue is resolved in version 2.63.0.
Potential Impact
An attacker with authenticated administrator access to any organization within the Casdoor system can bypass permission verification controls, potentially leading to unauthorized access and full compromise of confidentiality, integrity, and availability of the system. The CVSS score of 7.2 (high) reflects the network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade Casdoor to version 2.63.0 or later, where this vulnerability is fixed. No other mitigation or temporary workaround is indicated in the available data.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- mitre
- Date Reserved
- 2025-09-26T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 68e6b5002ff6d6ea8f108dd4
Added to database: 10/08/2025, 19:01:20 UTC
Last enriched: 07/05/2026, 21:36:18 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 220
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.