CVE-2026-9094
Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check
9.8
CRITICAL
CVSS 3.1
EPSS 0.42%
Description
Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.
How to fix CVE-2026-9094
To remediate CVE-2026-9094, upgrade the affected package to a fixed version below.
- —upgrade to 2.387.0 or later
Is CVE-2026-9094 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.387.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |