Skip to main content
CRITICAL

CVE-2026-91998

CVSS v3

9.9

CRITICAL

EPSS Score

0.6 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizations. Attackers can enumerate user records including password salts and email addresses, create administrator accounts, modify existing users, and delete them in any organization by supplying legitimate credentials from a single application.

Technical details

Published
2026-09-15
Last Modified
2026-09-15

Frequently asked questions

What is CVE-2026-91998?

Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizations. Attackers can enumerate user records including password salts and email addresses, create administrator accounts, modify existing users, and delete them in any organization by supplying legitimate credentials from a single application.

Is CVE-2026-91998 actively exploited?

Active exploitation of CVE-2026-91998 has not been confirmed. Its EPSS score was 0.6% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-91998?

CVE-2026-91998 has a CVSS v3 base score of 9.9 (CRITICAL severity).

Is CVE-2026-91998 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key