CVE-2026-105307
Deferred Deferred - Pending Action

Authentication Bypass in Casdoor API Endpoint

Vulnerability report for CVE-2026-105307, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulDB

Description

A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
n/a Casdoor 3.161.0
n/a Casdoor 3.161.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Casdoor versions up to 3.161.1. It involves a missing authentication issue in the ApiFilter function of the routers/authz_filter.go file. An attacker can exploit this remotely without authentication due to improper access control in the API endpoint.

Impact Analysis

An attacker could gain unauthorized access to sensitive data or perform actions on behalf of users. Since the exploit is public, the risk of active attacks is high. Systems using vulnerable Casdoor versions may be compromised remotely.

Compliance Impact

This vulnerability could lead to unauthorized data access or breaches, violating GDPR's data protection requirements and HIPAA's security rules. Non-compliance risks include fines, legal action, and reputational damage due to exposed sensitive data.

Mitigation Strategies

Upgrade Casdoor to a version beyond 3.161.1 where the vulnerability in routers/authz_filter.go has been patched. If an upgrade is not immediately possible, restrict network access to the API endpoint to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105307. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart