External risk intelligence

Casdoor Authorization Bypass Allows Unrestricted Cross-Organization User Administration

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-91998

Casdoor is an identity and access management platform designed to be deployed as an internet-facing service to handle authentication and user management. As an identity provider, its API endpoints are typically exposed to the network to facilitate integration with various applications, making this service a common candidate for public-facing deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability exists in Casdoor through version 4.4.0 that allows unauthorized access to user administration functions. If exploited, an attacker could gain broad control over user accounts across all organizations, including viewing sensitive information and creating or deleting administrators. The main concern is confirming relevance and exposure.

  • Bypass allows unauthorized user administration.
  • Critical vulnerability impacts identity management.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can leverage an authorization bypass in the API to achieve unrestricted access to user administration across all organizations. This is possible by using a legitimate `clientId` and `clientSecret` from any application. The attacker can then enumerate user details, create new administrators, or modify and delete existing user accounts within any organization.

  • Requires any application's credentials.
  • Triggered by accessing the `/api/mcp` endpoint.
  • Risk: Unrestricted user administration and data exposure.

Live Threat

Current exploitation, exposure, and threat context

The authorization bypass vulnerability in the /api/mcp endpoint could allow an attacker with valid application credentials to gain administrative control over user accounts across all organizations. This could lead to unauthorized modification, creation, or deletion of user data, including sensitive information such as password salts and email addresses.

  • User account data.
  • Unrestricted API access.
  • Compromise of user administration.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Casdoor deployments, potentially affecting application owners, platform teams, and security operations. The first practical step is to identify all Casdoor instances, determine their network exposure and business criticality, and confirm the accountable owner for each. Subsequent remediation planning should be risk-based, considering factors like maintenance windows and potential vendor coordination.

  • Identify affected Casdoor instances and owners.
  • Verify network exposure and business criticality.
  • Plan risk-based remediation and vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Casdoor and how is it used?

Casdoor is an open-source identity and access management (IAM) platform. It provides centralized authentication, user management, and authorization services for various web and mobile applications. It functions as an identity provider, allowing developers to manage user accounts, permissions, and organization-specific data in a unified system.

What is the vulnerability in CVE-2026-91998?

This vulnerability is an authorization bypass, classified as CWE-863. It means the software fails to properly verify that a user has the necessary permissions before granting access to specific functions. In this case, the system incorrectly trusts that anyone with valid application-level credentials has the authority to manage all users and organizations within the platform.

How is this Casdoor authorization bypass triggered?

The issue is triggered by making requests to the /api/mcp endpoint. An attacker does not need administrative credentials to succeed; they only need a legitimate clientId and clientSecret from any application configured in the platform. Conversely, requests that do not provide these specific application credentials will not trigger this bypass, as valid authentication is the prerequisite for the endpoint to process the request.

Is my Casdoor instance at risk?

According to Halo Surface Signal, Casdoor is typically deployed as an internet-facing service to enable integration with external applications, making public-facing instances highly relevant. If your instance is accessible from the network, it is a primary target. You should prioritize instances that handle authentication for external services or store sensitive user directories.

How do I start securing my environment?

Begin by creating an inventory of all your Casdoor instances to determine which are reachable from the network. Verify the business criticality of each instance and identify who owns or maintains them. Once mapped, coordinate with your team to plan a risk-based remediation strategy, focusing on restricting access or applying vendor-provided updates to mitigate the potential for unauthorized user administration.

References