VYPR
Medium severity5.3NVD Advisory· Published May 28, 2026· Updated Jun 17, 2026

CVE-2026-9091

CVE-2026-9091

Description

Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go calls HandleLoggedIn directly without invoking checkMfaEnable. Any user authenticating via this path is logged in without MFA enforcement.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/casdoor/casdoorGo
<= 1.1000.1-0.20260321120606-239e8bd69487

Affected products

3

Patches

Vulnerability mechanics

References

3

News mentions

1