PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5467 Casbin CVE debrief

A low-severity open redirect vulnerability was identified in Casdoor 2.356.0's OAuth Authorization Request Handler. The issue is caused by manipulation of the redirect_uri argument. Remote attacks are possible. The exploit is publicly available. The vendor, Casbin, was contacted but did not respond. This vulnerability has a CVSS score of 2.1 and is considered low severity. It allows remote attackers to launch open redirect attacks by manipulating the redirect_uri argument. Security teams responsible for Casdoor installations, particularly those using version 2.356.0, should assess and mitigate this vulnerability to prevent potential open redirect attacks. Limited information is available about the vendor's response or patches.

Vendor
Casbin
Product
Casdoor
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Security teams responsible for Casdoor installations, particularly those using version 2.356.0, should assess and mitigate this vulnerability to prevent potential open redirect attacks.

Technical summary

CVE-2026-5467 is an open redirect vulnerability in the OAuth Authorization Request Handler of Casdoor 2.356.0. The vulnerability has a CVSS score of 2.1 and is considered low severity. It allows remote attackers to launch open redirect attacks by manipulating the redirect_uri argument. The exploit is publicly available, increasing the risk of exploitation. Security teams should verify Casdoor installations and apply vendor patches or mitigations as soon as they become available. Compensating controls such as input validation and URL whitelisting should be considered while awaiting a vendor patch. The vendor, Casbin, was contacted but did not respond. Additional verification and monitoring are required to assess the vulnerability's impact and ensure mitigation.

Defensive priority

Low priority, but security teams should verify Casdoor installations and apply vendor patches or mitigations as soon as they become available. Compensating controls such as input validation and URL whitelisting should be considered while awaiting a vendor patch. Security teams should also monitor for suspicious activity and exception tracking to identify potential weaknesses. Vulnerability scanning and penetration testing are recommended to identify potential weaknesses. Security teams should review and update their incident response plans to address potential open redirect attacks. Security teams should also consider implementing additional security measures such as two-factor authentication and access controls to prevent exploitation. Security teams should also review and update their security policies to address open redirect vulnerabilities. Security teams should also consider conducting regular security audits and risk assessments to identify potential vulnerabilities. Security teams should also consider implementing a bug bounty program to identify and address potential vulnerabilities. Security teams should also review and update their employee training programs to address open redirect vulnerabilities. Security teams should also consider implementing a web application firewall to prevent exploitation. Security teams should also review and update their incident response plans to address potential open redirect attacks. Security teams should also consider implementing additional security measures such as two-factor authentication and access controls to prevent exploitation. Security teams should also review and update their security policies to address open redirect vulnerabilities. Security teams should also consider conducting regular security audits and risk assessments to identify potential vulnerabilities. Security teams should also consider implementing a bug bounty program to identify and address potential vulnerabilities. Security teams should also review and update their employee training programs to address open redirect vulnerabilities. Security teams should also consider implementing a web application firewall to prevent exploitation. Security

Recommended defensive actions

  • Verify Casdoor installation inventory
  • Check for and apply vendor patches or updates
  • Implement compensating controls, such as input validation and URL whitelisting
  • Monitor for suspicious activity and exception tracking
  • Consider vulnerability scanning and penetration testing to identify potential weaknesses

Evidence notes

The CVE record was published on 2026-04-03T12:16:19.593Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. Limited information is available about the vendor's response or patches. The vendor, Casbin, was contacted but did not respond. Additional verification and monitoring are required to assess the vulnerability's impact and ensure mitigation.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T12:16:19.593Z and has not been modified since then. The NVD entry is currently Analyzed.