CVE Explorer
CVE-2026-9093
In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"Casdoor","vendor":"Casdoor","versions":[{"lessThanOrEqual":"2.362.0","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:23e5203481409bc7bca40683378a401b9f644b8ec5c281c395584e5a60b3d6d2 · sha256:07cfc88170a28d00… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:23e5203481409bc7bca40683378a401b9f644b8ec5c281c395584e5a60b3d6d2 · sha256:07cfc88170a28d00… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"description":"CWE-863 Incorrect Authorization","lang":"en"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:23e5203481409bc7bca40683378a401b9f644b8ec5c281c395584e5a60b3d6d2 · sha256:07cfc88170a28d00… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://kb.cert.org/vuls/id/780781"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:23e5203481409bc7bca40683378a401b9f644b8ec5c281c395584e5a60b3d6d2 · sha256:07cfc88170a28d00… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.