← العودة للجدول
CVE-2026-9098
CVE-2026-9098 — VulnCheck: In Casdoor versions 2.362.0 and earlier, the SAML callback handler in
📅 2026-05-28
🔴 Critical 🔥 No VulnCheck APT APT CVSS 9.1

📋 الوصف الكامل

In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest previously issued by Casdoor. Additionally, if an administrator disables or deletes an IdP (Identity Provider) after a SAML flow has started, the handler still processes the response using the provid

💻 الأنظمة المتأثرة

VulnCheck: In Casdoor

⚠️ نوع التهديد

APT

🔗 CVE ID

CVE-2026-9098

📡 المصدر

VulnCheck

✅ الحلول والتخفيف

Update to v2.362.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←