CVE-2026-9094: Casdoor
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.
Affected products
- Casdoor Casdoor: up to and including 2.362.0
Published 2026-05-28. Last modified 2026-06-17.