← العودة للجدول
CVE-2026-9094
CVE-2026-9094 — VulnCheck: Casdoor versions 2.362.0 and earlier contain a vulnerability enabling
📅 2026-05-28
🔴 Critical 🔥 No VulnCheck Exploit Vulnerability CVSS 9.8

📋 الوصف الكامل

Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.

💻 الأنظمة المتأثرة

Microsoft Exchange

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-9094

📡 المصدر

VulnCheck

✅ الحلول والتخفيف

Update to v2.362.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←