Impact
Casdoor versions up to 4.4.0 contain an authorization bypass in the /api/mcp endpoint. An attacker who can obtain any application’s clientId and clientSecret can send requests to this endpoint and bypass all authorization checks. The flaw permits enumeration of all user records, including password salts and email addresses, and allows the attacker to create administrator accounts, modify existing users, or delete them in any organization. The weakness is identified as CWE‑863, a classic example of improper authorization.
Affected Systems
The affected product is Casdoor, vendor Casdoor, with vulnerable releases up to and including 4.4.0.
Risk and Exploitability
The vulnerability is scored 9.4 on the CVSS matrix, indicating critical severity. The EPSS score is <1% (0.00417), suggesting a low but nonzero probability of exploitation. The flaw is not listed in CISA’s KEV catalog, but its high CVSS score and the ease of credential abuse warrant a high risk assessment. Attackers could carry out the exploit remotely via HTTP requests to the exposed /api/mcp endpoint, potentially gaining full control over user identities in all organizations that use Casdoor.
OpenCVE Enrichment