Sceawere

Vulnerability Detail

CVE-2026-105307UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Casdoor ApiFilter Authentication Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
7h ago
Vendor
n/a
Product
Casdoor
Attack Type
Missing Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T12:17:09.380Z",
  "pubdate": "2026-10-05T12:17:09.380Z",
  "executiveSummary": "A critical authentication bypass vulnerability exists in the Casdoor authorization framework, specifically within the ApiFilter function located in routers/authz_filter.go.\nThe vulnerability allows remote, unauthenticated attackers to circumvent security controls, leading to unauthorized access to protected API endpoints.\nAffected products include Casdoor versions up to 3.161.1. The flaw presents a significant security risk, as it effectively nullifies the authentication layer intended to guard sensitive system resources.\nExploitation does not require prior authentication, and the vulnerability can be triggered remotely by crafting specific requests that bypass the logic implemented in the authz_filter.go module.\nDue to the public availability of exploit information and the vendor's lack of response, systems running vulnerable versions are at immediate risk of exploitation by unauthorized actors.",
  "technicalDetails": "The vulnerability resides in the ApiFilter function, which acts as a security middleware for API requests within Casdoor. The root cause stems from a flaw in the logic responsible for validating request tokens or session identifiers, which fails to correctly enforce authentication requirements under specific conditions.\nSpecifically, within routers/authz_filter.go, the filter logic can be manipulated to skip the mandatory authentication check, allowing an attacker to proceed as an authorized entity without providing valid credentials.\nThe attack flow initiates with a remote attacker targeting an API endpoint protected by the Casdoor authorization filter. By manipulating the request parameters or headers—or exploiting the specific logic flow that governs the bypass—the attacker effectively causes the ApiFilter to return a successful authorization state, even when no valid session is present.\nBecause the vulnerability is situated at the infrastructure layer (the routing and filtering stage), it applies globally to API endpoints routed through this filter. Once the filter is bypassed, the downstream logic processes the request as if it originated from a verified, privileged user.\nThe technical impact includes unauthorized access to data, potential modification of system settings, or the execution of administrative functions via API calls that should have been restricted. The absence of proper authorization checks essentially degrades the security posture of the application to 'public access' for those specific endpoints, regardless of their intended security policy.\nNo specific privilege or prior authentication is required to initiate this attack, making it highly accessible for remote exploitation. The exploit leverages the intrinsic trust the application places in the output of the ApiFilter function, which fails to act as a definitive gatekeeper."
}
CVE-2026-105307: Casdoor ApiFilter Authentication Bypass (HIGH Severity, CVSS: 7.3) | Sceawere