CRITICAL 9.6 CVE-2026-90942 Published 14 Sept 2026

Casdoor Admin Certificate Key Exposure

Worried this affects one of your servers?

Casdoor, a popular open-source identity provider, is affected by a security vulnerability in versions up to 4.4.0.

Casdoor fails to properly secure the instance-wide built-in certificate private key in the /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it.

Attackers can exploit this exposure to forge JWT tokens for any user in any organization, including global administrators.

Reference: CVE-2026-90942 on NVD

← Back to Security News