CRITICAL

CVE-2026-90942

2026-09-14 CVSS v3.1
CVSS
9.6

Description

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.21%
Probability of exploitation in next 30 days
11.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE