Skip to content
Threat Feed
high advisory

Authentication Bypass Vulnerability in Casdoor

A missing authentication vulnerability in Casdoor versions up to 3.161.1 allows remote attackers to bypass security controls via the ApiFilter function.

CVE search metadata

CVE search record: CVE-2026-105307. Severity: high. CVSS: 7.3. KEV: no. Product: Casdoor (<= 3.161.1). Brief: Authentication Bypass Vulnerability in Casdoor. Brief link: https://feed.craftedsignal.io/briefs/2026-10-casdoor-auth-bypass/

Casdoor versions up to and including 3.161.1 contain a critical security vulnerability in the ApiFilter function within the file routers/authz_filter.go. This component, which governs authorization logic for API endpoints, fails to properly enforce authentication, allowing unauthenticated remote attackers to interact with protected resources. The vulnerability is categorized as a missing authentication flaw, which can be exploited remotely without requiring valid credentials. Because the exploit mechanism is public and the vendor has not provided a response or patch, instances of Casdoor are at an elevated risk of unauthorized access and potential data exposure. Organizations running Casdoor should evaluate their exposure and implement compensating controls, such as limiting access to the API surface at the network edge.

Impact

Successful exploitation of this vulnerability allows unauthenticated remote attackers to bypass authentication controls, effectively granting them unauthorized access to sensitive application data and API functionality. Given the core role of Casdoor as an identity and access management system, this impact is severe and could facilitate lateral movement or data exfiltration across connected services.

Recommendation

  • Implement network-level restrictions using a Web Application Firewall (WAF) or reverse proxy to block unauthenticated requests to the API endpoints managed by Casdoor until a security patch is available.
  • Audit access logs for anomalous requests to API paths, particularly those that bypass standard authentication flows, to identify potential exploitation attempts.
  • Review the deployment environment for Casdoor to ensure it is not exposed to the public internet unless absolutely necessary.
  • Monitor the vendor repository for the release of an official security patch for versions 3.161.1 and earlier.

Immediate actions

Restrict access to Casdoor API endpoints at the network perimeter

IT Operations 24h

Mitigations

Apply network-level filtering to block unauthorized access to API routers

immediate IT Operations

CVE-2026-105307

Gaps

  • Lack of official vendor patch