CVE-2026-9094
Cross-Organization Token Exchange in Casdoor
Publication date: 2026-05-28
Last updated on: 2026-05-28
Assigner: CERT/CC
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| casdoor | casdoor | to 2.362.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Casdoor versions 2.362.0 and earlier. It involves the GetTokenExchangeToken function, which validates JWT signatures but fails to verify that the token's user belongs to the same organization as the target application.
As a result, an attacker can perform a cross-organization token exchange, allowing them to escalate privileges across organizational boundaries.
How can this vulnerability impact me? :
This vulnerability can lead to privilege escalation across organizational boundaries. An attacker could use a token from one organization to gain unauthorized access to resources or applications in another organization.
This unauthorized access could compromise sensitive data, disrupt services, or allow further exploitation within the affected systems.