External risk intelligence

Casdoor Certificate Endpoint Private Key Exposure Allows Token Forgery

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-90942

Casdoor is an open-source identity and access management (IAM) platform. IAM systems are designed to be internet-facing services to handle authentication, authorization, and single sign-on for web applications and APIs, making their management and API endpoints inherently public-facing or edge-reachable in typical deployments.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in Casdoor affects identity and access management systems, allowing an administrator to retrieve a critical private key. This key can then be used to forge authentication tokens for any user across any organization, potentially granting unauthorized access to global administrator privileges.

  • Private key exposure allows token forgery.
  • Critical for identity systems and broad access.
  • Confirm relevance and exposure for core systems.

Attack Path

How an attacker could exploit the issue

An attacker with administrator privileges within an organization could potentially access the Casdoor instance's certificate endpoints. These endpoints inadvertently expose the private key for the instance-wide built-in certificate. With this private key, an attacker could then forge JWT tokens, granting them the ability to impersonate any user, including global administrators, across all organizations within the Casdoor system.

  • Requires organization administrator access.
  • Accesses certificate API endpoints.
  • Risk of impersonating any user.

Live Threat

Current exploitation, exposure, and threat context

An organization administrator who can access specific Casdoor API endpoints could retrieve a built-in certificate's private key. This exposed key could then be used to forge JSON Web Tokens (JWTs) for any user within any organization, potentially including global administrators, when supported by the advisory's context.

  • Instance-wide private key could be exposed.
  • Administrators may retrieve the key via API.
  • Forged JWTs could grant unauthorized access.

Operational Fix

Recommended remediation, mitigation, and detection steps

The critical exposure of Casdoor's built-in certificate private key indicates that teams managing the Casdoor application, likely the platform or application owners, must prioritize this. The first practical step is to confirm where Casdoor is deployed, assess its internet reachability and business criticality, identify the specific system owners, and then plan remediation based on the assessed risk.

  • Identify application owners.
  • Verify exposed private key access.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Casdoor?

Casdoor is an open-source identity and access management (IAM) platform. Organizations use it to centralize authentication, authorization, and single sign-on capabilities for their web applications and APIs, effectively serving as the gatekeeper for user identities.

How does CVE-2026-90942 affect security?

This vulnerability, classified as Improper Authorization (CWE-863), occurs because Casdoor fails to properly mask an instance-wide private key within its certificate API endpoints. If retrieved, this key allows an attacker to forge JWT tokens, essentially enabling them to bypass authentication and impersonate any user, including high-privilege administrators.

What triggers this vulnerability?

The issue is triggered when a user with existing organization-level administrator privileges accesses the /api/get-certs or /api/get-cert endpoints. It does not occur for standard users without administrative rights, as they lack the necessary permissions to query these specific API paths.

Is my instance at risk?

According to Halo Surface Signal, because Casdoor is an IAM platform designed to handle authentication for web applications, its management interfaces and API endpoints are often inherently internet-facing. If your instance is reachable from the internet, the potential for unauthorized access by an organization administrator is elevated.

What should I do to respond?

Begin by identifying the system owners responsible for your Casdoor deployment. Verify if your instance uses the affected versions and assess its network reachability. Coordinate with your team to review the vendor's guidance, monitor for authorized updates, and restrict access to administrative API endpoints where possible.

References