SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-84423

HIGH · CVSS 7.3 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A high-severity vulnerability in Casdoor versions up to 4.0.0 affects the upload-resource API, allowing for missing authentication in an unknown function within the controllers/resource.go file. This flaw can be exploited remotely, posing a significant risk to systems utilizing this component. Organizations using Casdoor should prioritize immediate remediation efforts to mitigate potential unauthorized access and data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84423
Severity
HIGH
CVSS
7.3
EPSS
0.40%
GitHub

Original NVD Description

A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.