Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://kb.cert.org/vuls/id/780781 |
|
Fri, 29 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 CWE-749 CWE-862 |
Fri, 29 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-749 CWE-862 |
Fri, 29 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 28 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Casdoor
Casdoor casdoor |
|
| Vendors & Products |
Casdoor
Casdoor casdoor |
Thu, 28 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-749 CWE-862 |
Thu, 28 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go calls HandleLoggedIn directly without invoking checkMfaEnable. Any user authenticating via this path is logged in without MFA enforcement. | |
| Title | CVE-2026-9091 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-05-29T19:01:52.614Z
Reserved: 2026-05-20T15:04:03.933Z
Link: CVE-2026-9091
Updated: 2026-05-29T19:01:34.648Z
Status : Deferred
Published: 2026-05-28T17:16:33.953
Modified: 2026-05-29T20:16:31.587
Link: CVE-2026-9091
No data.
OpenCVE Enrichment
Updated: 2026-05-29T22:30:09Z