Description
A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Authentication bypass on Casdoor API endpoint
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the ApiFilter function of routers/authz_filter.go in Casdoor versions up to 3.161.1, where a missing authentication check allows an attacker to use the API endpoint without providing valid credentials. This can lead to unauthorized access to protected resources and data. The vulnerability is rated CVSS 6.9 and is exploitable from a remote location with publicly available attack code.

Affected Systems

Casdoor software, specifically all installations using version 3.161.1 or earlier, may be impacted. Upgrades beyond 3.161.1 are not known to contain the fix.

Risk and Exploitability

With a CVSS score of 6.9, the vulnerability presents medium to high risk. The exploit is publicly available, and the EPSS score is currently unavailable, but the lack of a KEV listing does not mitigate the potential for widespread abuse. Attackers can initiate the exploit remotely, bypassing authentication to gain unauthorized access.

Generated by OpenCVE AI on October 5, 2026 at 13:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Acquire and install the latest Casdoor release that addresses the authentication bypass.
  • Restrict unauthenticated API access using firewall rules or an API gateway.
  • Monitor API logs for anomalous activity and enforce mandatory authentication for all endpoints.

Generated by OpenCVE AI on October 5, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Casdoor API Endpoint authz_filter.go ApiFilter missing authentication
First Time appeared Casdoor
Casdoor casdoor
Weaknesses CWE-287
CWE-306
CPEs cpe:2.3:a:casdoor:casdoor:*:*:*:*:*:*:*:*
Vendors & Products Casdoor
Casdoor casdoor
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T15:28:37.748Z

Reserved: 2026-10-05T06:01:53.751Z

Link: CVE-2026-105307

cve-icon Vulnrichment

Updated: 2026-10-05T15:26:35.106Z

cve-icon NVD

Status : Deferred

Published: 2026-10-05T12:17:09.380

Modified: 2026-10-05T16:17:12.323

Link: CVE-2026-105307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T13:30:19Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function