← العودة للجدول
CVE-2026-9093
CVE-2026-9093 — VulnCheck: In Casdoor versions 2.362.0 and earlier, the SAML service provider imp
📅 2026-05-28
🔴 Critical 🔥 No VulnCheck Exploit Vulnerability CVSS 9.8

📋 الوصف الكامل

In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor.

💻 الأنظمة المتأثرة

VulnCheck: In Casdoor

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-9093

📡 المصدر

VulnCheck

✅ الحلول والتخفيف

Update to v2.362.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←