CVE-2026-105307: Casdoor API Endpoint authz_filter.go ApiFilter missing authentication
A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authzfilter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be considered exposed?
Casdoor deployments running versions up to 3.161.1 should be considered affected, specifically where the API endpoint uses the ApiFilter function in routers/authz_filter.go.
Does exploitation require credentials or user interaction?
No. The issue can be exploited remotely with no required privileges or user interaction.
Is exploit activity likely to be practical?
A public exploit is available and may be used. The reported impact includes loss of confidentiality, integrity, and availability.