PatchSiren cyber security CVE debrief
CVE-2026-5467 Casbin CVE debrief
A low-severity open redirect vulnerability was identified in Casdoor 2.356.0's OAuth Authorization Request Handler. The issue is caused by manipulation of the redirect_uri argument. Remote attacks are possible. The exploit is publicly available. The vendor, Casbin, was contacted but did not respond. This vulnerability has a CVSS score of 2.1 and is considered low severity. It allows remote attackers to launch open redirect attacks by manipulating the redirect_uri argument. Security teams responsible for Casdoor installations, particularly those using version 2.356.0, should assess and mitigate this vulnerability to prevent potential open redirect attacks. Limited information is available about the vendor's response or patches.
- Vendor
- Casbin
- Product
- Casdoor
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Security teams responsible for Casdoor installations, particularly those using version 2.356.0, should assess and mitigate this vulnerability to prevent potential open redirect attacks.
Technical summary
CVE-2026-5467 is an open redirect vulnerability in the OAuth Authorization Request Handler of Casdoor 2.356.0. The vulnerability has a CVSS score of 2.1 and is considered low severity. It allows remote attackers to launch open redirect attacks by manipulating the redirect_uri argument. The exploit is publicly available, increasing the risk of exploitation. Security teams should verify Casdoor installations and apply vendor patches or mitigations as soon as they become available. Compensating controls such as input validation and URL whitelisting should be considered while awaiting a vendor patch. The vendor, Casbin, was contacted but did not respond. Additional verification and monitoring are required to assess the vulnerability's impact and ensure mitigation.
Defensive priority
Low priority, but security teams should verify Casdoor installations and apply vendor patches or mitigations as soon as they become available. Compensating controls such as input validation and URL whitelisting should be considered while awaiting a vendor patch. Security teams should also monitor for suspicious activity and exception tracking to identify potential weaknesses. Vulnerability scanning and penetration testing are recommended to identify potential weaknesses. Security teams should review and update their incident response plans to address potential open redirect attacks. Security teams should also consider implementing additional security measures such as two-factor authentication and access controls to prevent exploitation. Security teams should also review and update their security policies to address open redirect vulnerabilities. Security teams should also consider conducting regular security audits and risk assessments to identify potential vulnerabilities. Security teams should also consider implementing a bug bounty program to identify and address potential vulnerabilities. Security teams should also review and update their employee training programs to address open redirect vulnerabilities. Security teams should also consider implementing a web application firewall to prevent exploitation. Security teams should also review and update their incident response plans to address potential open redirect attacks. Security teams should also consider implementing additional security measures such as two-factor authentication and access controls to prevent exploitation. Security teams should also review and update their security policies to address open redirect vulnerabilities. Security teams should also consider conducting regular security audits and risk assessments to identify potential vulnerabilities. Security teams should also consider implementing a bug bounty program to identify and address potential vulnerabilities. Security teams should also review and update their employee training programs to address open redirect vulnerabilities. Security teams should also consider implementing a web application firewall to prevent exploitation. Security
Recommended defensive actions
- Verify Casdoor installation inventory
- Check for and apply vendor patches or updates
- Implement compensating controls, such as input validation and URL whitelisting
- Monitor for suspicious activity and exception tracking
- Consider vulnerability scanning and penetration testing to identify potential weaknesses
Evidence notes
The CVE record was published on 2026-04-03T12:16:19.593Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. Limited information is available about the vendor's response or patches. The vendor, Casbin, was contacted but did not respond. Additional verification and monitoring are required to assess the vulnerability's impact and ensure mitigation.
Official resources
-
CVE-2026-5467 CVE record
CVE.org
-
CVE-2026-5467 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Source reference
[email protected] - Permissions Required, VDB Entry
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T12:16:19.593Z and has not been modified since then. The NVD entry is currently Analyzed.