Authorization Bypass in Casdoor Affects User Administration Functionality
CVE-2026-91998
Key Information:
Badges
What is CVE-2026-91998?
Casdoor version 4.4.0 contains a critical authorization bypass vulnerability in the /api/mcp endpoint. This flaw potentially allows attackers with knowledge of any application's clientId and clientSecret to gain unrestricted administrative access across all organizations within the platform. By exploiting this vulnerability, an attacker could enumerate sensitive user records, including password salts and email addresses, create new administrator accounts, modify existing user permissions, and even delete user accounts entirely within any organization by leveraging legitimate application credentials.
Affected Version(s)
casdoor 0 <= 4.4.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
