<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Casdoor (&lt;= 4.4.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/casdoor--4.4.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 13:40:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/casdoor--4.4.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass Vulnerability in Casdoor /api/mcp Endpoint</title><link>https://feed.craftedsignal.io/briefs/2026-09-casdoor-auth-bypass/</link><pubDate>Tue, 15 Sep 2026 13:40:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-casdoor-auth-bypass/</guid><description>Casdoor versions through 4.4.0 contain an authorization bypass vulnerability (CVE-2026-91998) in the /api/mcp endpoint, allowing authenticated attackers to perform unauthorized administrative actions across all organizations.</description><content:encoded><![CDATA[<p>Casdoor versions up to and including 4.4.0 are affected by a severe authorization bypass vulnerability (CVE-2026-91998) located within the /api/mcp endpoint. This vulnerability allows an attacker who possesses valid credentials (clientId and clientSecret) for any single application registered within the Casdoor instance to gain elevated administrative privileges.</p>
<p>By exploiting this flaw, an attacker can bypass scope restrictions and access administrative functions across all organizations managed by the Casdoor instance. This includes the ability to enumerate sensitive user records, such as email addresses and password salts, as well as the capability to create, modify, or delete administrator accounts. Because this exploit allows for arbitrary account manipulation, it poses a significant risk to the integrity of identity management systems using Casdoor. Defenders should prioritize patching or restricting access to the affected endpoint until an update is applied.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS v3.1 base score of 9.9. Successful exploitation allows for full administrative control over the Casdoor identity management environment. An attacker can gain unauthorized access to all user information, perform account takeover by modifying credentials, or delete existing users, potentially leading to widespread service disruption or credential theft across all connected organizations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately upgrade Casdoor to a version patched against CVE-2026-91998.</li>
<li>Audit access logs for the /api/mcp endpoint to identify requests originating from unauthorized clientId/clientSecret combinations or requests targeting organizations outside the scope of the authenticated client.</li>
<li>Monitor for suspicious administrative account creation or modification events occurring across all organizations simultaneously.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>