CVE-2026-9096: High severity Casdoor Casdoor vulnerability

Published May 28, 2026
·
Updated

Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlResponse() never reads this field, meaning that time bounds are computed by the library but silently discarded before the user session is issued.

Affected Software

1 affected component
Casdoor Casdoor<=2.362.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Casdoor to a version that resolves this vulnerability.

    Fixed in 2.362.0
  2. Configuration

    Update the SAML response handling so that ParseSamlResponse() failures/warnings reported in assertionInfo.WarningInfo for NotOnOrAfter and NotBefore are enforced when issuing the user session (instead of silently discarding time-bound validation results).

    gosaml2 / Casdoor SAML handling ParseSamlResponse() assertionInfo.WarningInfo handling = Treat NotOnOrAfter and NotBefore validation results as authoritative (do not ignore assertionInfo.WarningInfo)

Event History

May 28, 2026
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverity
Jun 29, 58424
Event
via FIRST·07:01 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-9096?

CVE-2026-9096 has a risk rating of 20, indicating a critical vulnerability.

2

How do I fix CVE-2026-9096?

To fix CVE-2026-9096, upgrade to Casdoor versions later than 2.362.0 that properly enforce SAML assertion time bounds.

3

What software is affected by CVE-2026-9096?

CVE-2026-9096 affects Casdoor versions 2.362.0 and earlier.

4

What protections are bypassed in CVE-2026-9096?

CVE-2026-9096 allows attackers to bypass SAML assertion time validation due to the implementation error in ParseSamlResponse().

5

What is the potential impact of CVE-2026-9096?

The potential impact of CVE-2026-9096 includes unauthorized access or exploitation due to improperly validated SAML assertions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203