CVE-2026-9091: Medium severity Casdoor Casdoor vulnerability
Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go calls HandleLoggedIn directly without invoking checkMfaEnable. Any user authenticating via this path is logged in without MFA enforcement.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Casdoorto a version that resolves this vulnerability.Fixed in 2.362.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9091?
The severity of CVE-2026-9091 is classified as medium with a score of 5.3.
How does CVE-2026-9091 affect users?
CVE-2026-9091 allows users to bypass configured multi-factor authentication (MFA) requirements during the social-login binding flow.
What versions are affected by CVE-2026-9091?
CVE-2026-9091 affects Casdoor versions 2.362.0 and earlier.
How do I fix CVE-2026-9091?
To fix CVE-2026-9091, upgrade to a version of Casdoor later than 2.362.0 that addresses the identified logic flaw.
What is the potential impact of exploiting CVE-2026-9091?
Exploiting CVE-2026-9091 could allow unauthorized access by bypassing MFA, increasing the risk of account compromise.