{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/casdoor--4.4.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:casdoor:casdoor:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-91998"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=CVE-2026-91998\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Casdoor (\u003c= 4.4.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Casdoor"],"content_html":"\u003cp\u003eCasdoor versions up to and including 4.4.0 are affected by a severe authorization bypass vulnerability (CVE-2026-91998) located within the /api/mcp endpoint. This vulnerability allows an attacker who possesses valid credentials (clientId and clientSecret) for any single application registered within the Casdoor instance to gain elevated administrative privileges.\u003c/p\u003e\n\u003cp\u003eBy exploiting this flaw, an attacker can bypass scope restrictions and access administrative functions across all organizations managed by the Casdoor instance. This includes the ability to enumerate sensitive user records, such as email addresses and password salts, as well as the capability to create, modify, or delete administrator accounts. Because this exploit allows for arbitrary account manipulation, it poses a significant risk to the integrity of identity management systems using Casdoor. Defenders should prioritize patching or restricting access to the affected endpoint until an update is applied.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 9.9. Successful exploitation allows for full administrative control over the Casdoor identity management environment. An attacker can gain unauthorized access to all user information, perform account takeover by modifying credentials, or delete existing users, potentially leading to widespread service disruption or credential theft across all connected organizations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade Casdoor to a version patched against CVE-2026-91998.\u003c/li\u003e\n\u003cli\u003eAudit access logs for the /api/mcp endpoint to identify requests originating from unauthorized clientId/clientSecret combinations or requests targeting organizations outside the scope of the authenticated client.\u003c/li\u003e\n\u003cli\u003eMonitor for suspicious administrative account creation or modification events occurring across all organizations simultaneously.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T15:31:29Z","date_published":"2026-09-15T13:40:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-casdoor-auth-bypass/","summary":"Casdoor versions through 4.4.0 contain an authorization bypass vulnerability (CVE-2026-91998) in the /api/mcp endpoint, allowing authenticated attackers to perform unauthorized administrative actions across all organizations.","title":"Authorization Bypass Vulnerability in Casdoor /api/mcp Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-09-casdoor-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Casdoor (\u003c= 4.4.0)","version":"https://jsonfeed.org/version/1.1"}