CRITICAL
9.6 CVE-2026-90942 Published 14 Sept 2026
Casdoor Admin Certificate Key Exposure
Worried this affects one of your servers?
Casdoor, a popular open-source identity provider, is affected by a security vulnerability in versions up to 4.4.0.
Casdoor fails to properly secure the instance-wide built-in certificate private key in the /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it.
Attackers can exploit this exposure to forge JWT tokens for any user in any organization, including global administrators.
Reference: CVE-2026-90942 on NVD
← Back to Security News