Vulnerability GO-2026-5896
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 months ago
July 07, 2026 at 03:26 PM UTC
Casdoor allows users to bypass configured MFA requirements in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0
v1.0.0 - v1.1000.0
Summary
Casdoor allows users to bypass configured MFA requirements in github.com/casdoor/casdoor
Details
Casdoor allows users to bypass configured MFA requirements in github.com/casdoor/casdoor
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 months ago
Casdoor: Arbitrary file write possible through Local File System storage provider in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5945
v1.0.0 - v1.1000.0 GO-2026-5945
Unknown
2 months ago
Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5953
v1.0.0 - v1.1000.0 GO-2026-5953
Unknown
3 months ago
Casdoor doesn't verify that a JWT used for token exchange is still active in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5892
v1.0.0 - v1.1000.0 GO-2026-5892
Unknown
3 months ago
Casdoor does not validate the AudienceRestriction element in SAML assertions in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5894
v1.0.0 - v1.1000.0 GO-2026-5894
Unknown
3 months ago
Casdoor has an authentication bypass in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5895
v1.0.0 - v1.1000.0 GO-2026-5895
Impacted packages
Timeline
Published
3 months ago
July 07, 2026 at 03:26 PM UTC
Last Modified
3 months ago
July 07, 2026 at 04:00 PM UTC