Record summary

CVE-2026-9092 has a selected CVSS score of 9.1 (critical).

Description

Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without checking the email_verified claim from upstream providers; the idp.UserInfo struct does not even include a EmailVerified field. An attacker can supply an unverified email claim from an upstream provider to take over accounts that use the same email address.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 1, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListThrough 2.362.0affected

References

2