CRITICAL 9.3 NVD

CVE-2026-90942

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organiza

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.

References

Published: 2026-09-14 · Source: NVD · Feed updated: 2026-09-15
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-14 via NVD.

Risk Timeline

CVE Disclosed2026-09-14 · 0 days ago

Remediation Resources

vulnfeed aggregates 10822 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.