Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 18:20
Updated : 2026-09-14 19:18
NVD link : CVE-2026-90942
Mitre link : CVE-2026-90942
CVE.ORG link : CVE-2026-90942
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
