Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-9093

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published May 28, 2026
Vendor unknown

Description

In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor.

References