CVE-2026-15630
N/A
N/A
Summary
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Casdoor | Casdoor | 0 <= v3.115.0 | affected |
Weaknesses
- CWE-863 Incorrect Authorization
- CWE-269 Improper Privilege Management
- CWE-639 Authorization Bypass Through User-Controlled Key
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.