CVE-2026-15630: Casdoor

Critical severity, CVSS 9.9. EPSS: 0.3% chance of exploitation in the next 30 days.

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

Affected products

  • Casdoor Casdoor: before v4.2.0 (fixed in v4.2.0)

Published 2026-07-23. Last modified 2026-09-22.