CVE-2026-6815

An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the application's intended storage sandbox.
References
Link Resource
https://kb.cert.org/vuls/id/937808 Third Party Advisory VDB Entry
https://www.kb.cert.org/vuls/id/937808 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:casbin:casdoor:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-11 16:17

Updated : 2026-06-17 11:01


NVD link : CVE-2026-6815

Mitre link : CVE-2026-6815

CVE.ORG link : CVE-2026-6815


JSON object : View

Products Affected

casbin

  • casdoor
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')