CRITICAL
9.9 CVE-2026-91998 Published 15 Sept 2026
Casdoor Authorization Bypass Bug
Worried this affects your website?
Casdoor versions up to 4.4.0 contain a serious vulnerability.
Attackers can exploit the /api/mcp endpoint to gain full access to user administration across all organizations.
This allows them to enumerate user records, create administrator accounts, modify existing users, and delete them.
All it takes is legitimate credentials from a single application.
Reference: CVE-2026-91998 on NVD
← Back to Security News