Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators. | |
| Title | Casdoor through 4.4.0 Private Key Exposure via Certificate Endpoints | |
| First Time appeared |
Casbin
Casbin casdoor |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:casbin:casdoor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Casbin
Casbin casdoor |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T19:07:57.306Z
Reserved: 2026-09-14T11:34:24.687Z
Link: CVE-2026-90942
Updated: 2026-09-14T19:07:50.868Z
Status : Received
Published: 2026-09-14T18:20:28.720
Modified: 2026-09-14T19:18:13.480
Link: CVE-2026-90942
No data.
OpenCVE Enrichment
No data.
