CRITICAL 9.9 CVE-2026-91998 Published 15 Sept 2026

Casdoor Authorization Bypass Bug

Worried this affects your website?

Casdoor versions up to 4.4.0 contain a serious vulnerability.

Attackers can exploit the /api/mcp endpoint to gain full access to user administration across all organizations.

This allows them to enumerate user records, create administrator accounts, modify existing users, and delete them.

All it takes is legitimate credentials from a single application.

Reference: CVE-2026-91998 on NVD

← Back to Security News