CVE-2026-90942 PUBLISHED

Casdoor through 4.4.0 Private Key Exposure via Certificate Endpoints

Assigner: VulnCheck
Reserved: 14.09.2026 Published: 14.09.2026 Updated: 14.09.2026

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
CVSS Score: 9.3

Product Status

Vendor casdoor
Product casdoor
Versions Default: unaffected
  • affected from 0 to 4.4.0 (incl.)

Credits

  • George Chen reporter

References

Problem Types

  • Incorrect Authorization CWE