Casdoor Authentication Bypass Vulnerability via Arbitrary Signing Certificates

Vulnerability

An authentication bypass vulnerability has been identified in Casdoor versions through 2.362.0. This issue arises because the buildSpCertificateStore function extracts X.509 certificates directly from incoming SAML responses, rather than using a trusted, pre-configured Identity Provider certificate. As a result, attackers can supply their own signing certificates to forge assertions, bypassing authentication controls.

Impact

Exploitation of this vulnerability allows attackers to impersonate users by forging SAML assertions, including those of administrators, and bypass authentication requirements such as multi-factor authentication.

Added: May 28, 2026, 5:47 PM
Updated: May 28, 2026, 5:47 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
5.0
exploitability
7.6
remediation
0.0
relevance
9.2
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.