CVE-2026-9092 | Casdoor up to 2.362.0 Email Address getExistUserByBindingRule EmailVerified authentication spoofing

SecurityVulns

A vulnerability, which was classified as critical, has been found in Casdoor up to 2.362.0. This impacts the function getExistUserByBindingRule of the component Email Address Handler. The manipulation of the argument EmailVerified leads to authentication bypass by spoofing.

This vulnerability is referenced as CVE-2026-9092. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More