{"id":"CVE-2026-9091","aliases":["GO-2026-5896"],"url":"https://o3.security/vulnerability/CVE-2026-9091","summary":"Casdoor allows users to bypass configured MFA requirements","details":"Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go calls HandleLoggedIn directly without invoking checkMfaEnable. Any user authenticating via this path is logged in without MFA enforcement.","published":"2026-05-28T18:30:32Z","modified":"2026-07-07T16:11:23.584657141Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":{"score":0.00322,"percentile":0.24436,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/casdoor/casdoor","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9091"},{"type":"PACKAGE","url":"https://github.com/casdoor/casdoor"},{"type":"WEB","url":"https://kb.cert.org/vuls/id/780781"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T16:11:23.584657141Z"}}