logo

Critical Casdoor Vulnerability CVE-2026-44213 Allows Arbitrary File Overwrites

ID: a409fd30-d694-5c96-8ee7-2aa99157c201

STIX ID: report--a409fd30-d694-5c96-8ee7-2aa99157c201

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Ddos

...
...

A critical arbitrary file-write vulnerability (CVE-2026-44213) in Casdoor's Local File System storage provider permits authenticated users with upload privileges to perform path traversal via unsanitized pathPrefix/fullFilePath parameters to /api/upload-resource, enabling creation or overwrite of arbitrary files on the host (possible persistence, cron jobs, database corruption, and escalation to full host compromise). Administrators are advised to restrict service account permissions, limit administrative access, and avoid or disable local storage until proper path validation is implemented.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.