CVE-2026-9090
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.1epss 0.2%
from disclosure to weapon37 days
Published on NVDMay 28
1st PoC+37d
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts the X.509 certificate directly from the incoming SAMLResponse instead of using the trusted pre-configured Identity Provider certificate, allowing an attacker to forge assertions signed with an attacker-controlled key.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
Casdoor · Casdoorpublic PoCs found — 1
githubgithub.com/biosGit/CVE-2026-9090★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://kb.cert.org/vuls/id/780781