CVE-2026-9094
Deferred Deferred - Pending Action
Cross-Organization Token Exchange in Casdoor

Publication date: 2026-05-28

Last updated on: 2026-06-02

Assigner: CERT/CC

Description
Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-28
Last Modified
2026-06-02
Generated
2026-06-18
AI Q&A
2026-05-28
EPSS Evaluated
2026-06-16
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
casdoor casdoor to 2.362.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in Casdoor versions 2.362.0 and earlier. It involves the GetTokenExchangeToken function, which validates JWT signatures but fails to verify that the token's user belongs to the same organization as the target application.

As a result, an attacker can perform a cross-organization token exchange, allowing them to escalate privileges across organizational boundaries.

Impact Analysis

This vulnerability can lead to privilege escalation across organizational boundaries. An attacker could use a token from one organization to gain unauthorized access to resources or applications in another organization.

This unauthorized access could compromise sensitive data, disrupt services, or allow further exploitation within the affected systems.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9094. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart