← back
CVE-2026-9090critical

CVE-2026-9090

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.1epss 0.2%
from disclosure to weapon37 days
Published on NVDMay 28
1st PoC+37d
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts the X.509 certificate directly from the incoming SAMLResponse instead of using the trusted pre-configured Identity Provider certificate, allowing an attacker to forge assertions signed with an attacker-controlled key.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
Casdoor · Casdoor
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.