CVE-2026-91998
Received Received - Intake

Authorization Bypass in Casdoor via /api/mcp Endpoint

Vulnerability report for CVE-2026-91998, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulnCheck

Description

Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizations. Attackers can enumerate user records including password salts and email addresses, create administrator accounts, modify existing users, and delete them in any organization by supplying legitimate credentials from a single application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
casdoor casdoor to 4.4.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-91998 is an authorization bypass vulnerability in Casdoor through version 4.4.0. It allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizations. Attackers can enumerate user records including password salts and email addresses, create administrator accounts, modify existing users, and delete them in any organization by supplying legitimate credentials from a single application.

Detection Guidance

Check Casdoor logs for unauthorized access to /api/mcp endpoint. Monitor for unusual user creation, modification, or deletion across organizations. Inspect network traffic for requests containing clientId and clientSecret parameters targeting /api/mcp.

Impact Analysis

This vulnerability allows attackers to fully control user accounts across all organizations in a Casdoor instance. They can create backdoor admin accounts, steal sensitive user data like password salts and emails, modify or delete users, and potentially escalate privileges. This compromises the integrity and confidentiality of the entire identity management system.

Compliance Impact

This vulnerability severely impacts compliance with GDPR and HIPAA by enabling unauthorized access to sensitive personal data. GDPR requires strict access controls and data protection measures, while HIPAA mandates safeguards for protected health information. The flaw allows attackers to exfiltrate, modify, or delete such data, leading to potential violations and regulatory penalties.

Mitigation Strategies

Upgrade Casdoor to a version beyond 4.4.0 immediately. Disable or restrict access to the /api/mcp endpoint via firewall or network policies. Rotate all clientId and clientSecret credentials for applications. Review and remove unauthorized administrator accounts created through this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91998. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart