Home

Description

Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go calls HandleLoggedIn directly without invoking checkMfaEnable. Any user authenticating via this path is logged in without MFA enforcement.

PUBLISHED Reserved 2026-05-20 | Published 2026-05-28 | Updated 2026-05-29 | Assigner certcc

Problem types

CWE-306 Missing Authentication for Critical Function

Product status

Any version
affected

References

kb.cert.org/vuls/id/780781

cve.org (CVE-2026-9091)

nvd.nist.gov (CVE-2026-9091)

Download JSON