Skip to main content
CRITICAL

CVE-2026-90942

CVSS v3

9.6

CRITICAL

EPSS Score

0.3 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.

Technical details

Published
2026-09-14
Last Modified
2026-09-14

Frequently asked questions

What is CVE-2026-90942?

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.

Is CVE-2026-90942 actively exploited?

Active exploitation of CVE-2026-90942 has not been confirmed. Its EPSS score was 0.3% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-90942?

CVE-2026-90942 has a CVSS v3 base score of 9.6 (CRITICAL severity).

Is CVE-2026-90942 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key