CVE-2026-6815
An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the application's intended storage sandbox.
- Affected products
- Casdoor
- Casbin Casdoor
- β€ 2.328.0
- CVSS 3.1
- 5.9 MEDIUM
- EPSS
- 0.5% (41th percentile)
- Weakness
- CWE-22
- NVD status
- Analyzed
- Published
- 2026-05-11
CVE-2026-6815 at NVD
6 known exploits for CVE-2026-6815
Proof-of-concept code and exploit modules indexed by Sploitus