CVE•Published 2026-05-28•Modified 2026-06-01•1 article on news•5 live references•NVD data
CVE-2026-9092
Vulnerability data via NVD (ingested)
CVSS v3.1
9.1
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS percentile
—
Description
Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without checking the email_verified claim from upstream providers; the idp.UserInfo struct does not even include a EmailVerified field. An attacker can supply an unverified email claim from an upstream provider to take over accounts that use the same email address.
Timeline
Published 2026-05-28
Modified 2026-06-01
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
More intel sources (5)
Shodan report
vuln:CVE-2026-9092Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-9092Censys host search filtered to this CVE id.
grep.app
CVE-2026-9092Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-9092GitHub code search for direct mentions.
Google dork
"CVE-2026-9092" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (8)
CVE-2026-90928 repos
praetorian-inc/brutusGo
Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native nerva/naabu pipeline …
amrudesh1/morfGo
Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and developers identify and address sens…
tycloud97/awesome-starsunknown
A curated list of my GitHub stars by stargazed
mooyoul/awesome-starsunknown
A curated list of my GitHub stars
harsh-bothra/netrikPython
Netrik — Nmap-driven internal-network service penetration testing (detection-only). See Beyond the Network.
ysy0915/chat-systemJava
多模型协作与智能辩论平台 — Multi-Agent 并行工作流 + RAG + 知识图谱,让多个 AI 像专家团队一样辩论、推理、共创
dinosn/kafka-security-auditPython
Apache Kafka — Security Audit using Raptor Loop Hunt, https://github.com/dinosn/raptor-loop-hunt
sandraschi/unity3d-mcpPython
FastMCP Unity 3D automation server plus webapp with VRM avatar pipeline and VRChat integration