Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the JWT signature and parses its claims, but never queries the Token table to verify whether the subject token has been revoked or invalidated. Because the revocation check is entirely absent, administrators are unable to terminate active sessions or revoke compromised tokens.
References
History

Wed, 03 Jun 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 02 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 02 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 May 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 28 May 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 28 May 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862

Thu, 28 May 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Casdoor
Casdoor casdoor
Weaknesses CWE-284
CWE-862
Vendors & Products Casdoor
Casdoor casdoor

Thu, 28 May 2026 17:00:00 +0000

Type Values Removed Values Added
Description Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the JWT signature and parses its claims, but never queries the Token table to verify whether the subject token has been revoked or invalidated. Because the revocation check is entirely absent, administrators are unable to terminate active sessions or revoke compromised tokens.
Title CVE-2026-9097
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-06-02T16:43:52.777Z

Reserved: 2026-05-20T15:05:12.699Z

Link: CVE-2026-9097

cve-icon Vulnrichment

Updated: 2026-06-02T15:50:00.643Z

cve-icon NVD

Status : Deferred

Published: 2026-05-28T17:16:34.767

Modified: 2026-06-02T17:16:39.050

Link: CVE-2026-9097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T04:45:25Z