Description
Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.
Published: 2026-09-14
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Identity theft and authorization escalation via forged JWT tokens
Action: Patch Immediately
AI Analysis

Impact

Casdoor up to and including version 4.4.0 fails to mask the instance-wide private key used for JWT signing in the /api/get-certs and /api/get-cert endpoints. This allows any organization administrator to retrieve the key. With the private key in hand, an attacker can forge JWT tokens that are accepted by the platform as if they were issued by a legitimate user or global administrator, enabling bypass of access controls and unauthorized data access.

Affected Systems

The affected product is Casdoor, a single sign-on solution developed by casbin:casdoor. All installations running version 4.4.0 or earlier are susceptible; newer releases contain the patch that properly obscures the key. No specific subrange beyond the stated major release is provided in the CNA data.

Risk and Exploitability

The CVSS v3.1 score of 9.3 indicates critical severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, but that does not lessen its potential impact. The flaw can be exploited by any authenticated user with organization- administrator privileges who can call the exposed API endpoints, making the attack vector one of legitimate API usage by privileged accounts. An attacker who gains such privileges can capture the key, generate arbitrary JWTs, impersonate users, and potentially control any organization’s resources.

Generated by OpenCVE AI on September 15, 2026 at 12:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched Casdoor release (4.5.0 or later).
  • If upgrading is not possible, restrict or remove access to the /api/get-certs and /api/get-cert endpoints by configuring the application or network to deny all but essential services.
  • Regenerate JWT signing keys for all users, then revoke or invalidate tokens issued before the fix so that any compromised key is no longer usable.

Generated by OpenCVE AI on September 15, 2026 at 12:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Casdoor
Casdoor casdoor
Vendors & Products Casdoor
Casdoor casdoor

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.
Title Casdoor through 4.4.0 Private Key Exposure via Certificate Endpoints
First Time appeared Casbin
Casbin casdoor
Weaknesses CWE-863
CPEs cpe:2.3:a:casbin:casdoor:*:*:*:*:*:*:*:*
Vendors & Products Casbin
Casbin casdoor
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:03.810Z

Reserved: 2026-09-14T11:34:24.687Z

Link: CVE-2026-90942

cve-icon Vulnrichment

Updated: 2026-09-14T19:07:50.868Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:20:28.720

Modified: 2026-09-23T17:17:44.670

Link: CVE-2026-90942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T13:00:17Z

Weaknesses