Vulnerability intelligence
CVE-2026-9094
Casdoor Casdoor
Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
0.4%
Riskier than 35% of all CVEs · checked 2026-09-08
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jun 2, 2026 · latest Jun 2, 2026
Coverage timeline
-
Severe Casdoor Identity Platform Flaws Expose Corporate Networkssecurityonline.info · Jun 2, 2026