← العودة للجدول
CVE-2026-9092
CVE-2026-9092 — VulnCheck: Casdoor versions 2.362.0 and earlier contain a vulnerability involving
📅 2026-05-28
🔴 Critical 🔥 No VulnCheck Exploit Vulnerability CVSS 9.1

📋 الوصف الكامل

Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without checking the email_verified claim from upstream providers; the idp.UserInfo struct does not even include a EmailVerified field. An attacker can supply an unverified email claim from an upstream provid

💻 الأنظمة المتأثرة

VulnCheck: Casdoor versions

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-9092

📡 المصدر

VulnCheck

✅ الحلول والتخفيف

Update to v2.362.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←