CVE-2026-9094
Received Received - Intake
Cross-Organization Token Exchange in Casdoor

Publication date: 2026-05-28

Last updated on: 2026-05-28

Assigner: CERT/CC

Description
Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-28
Last Modified
2026-05-28
Generated
2026-05-28
AI Q&A
2026-05-28
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
casdoor casdoor to 2.362.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in Casdoor versions 2.362.0 and earlier. It involves the GetTokenExchangeToken function, which validates JWT signatures but fails to verify that the token's user belongs to the same organization as the target application.

As a result, an attacker can perform a cross-organization token exchange, allowing them to escalate privileges across organizational boundaries.


How can this vulnerability impact me? :

This vulnerability can lead to privilege escalation across organizational boundaries. An attacker could use a token from one organization to gain unauthorized access to resources or applications in another organization.

This unauthorized access could compromise sensitive data, disrupt services, or allow further exploitation within the affected systems.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart