CVE-2026-6815Disclosure(casbin / casdoor)

HIGHCVSS 5.9 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for casbin casdoor systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the application's intended storage sandbox.

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • casdoor

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-11); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
casdoor

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-11: 2Mentions · 2026-07-17: 1PoC Mentioned / Linked · 2026-07-17: 1Exploit Tool / Code · 2026-07-17: 1Active Exploitation · 2026-07-17: 1Technical Details · 2026-05-11: 2Technical Details · 2026-07-17: 105-1107-17
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Active Exploitation
133.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-112
Disclosure1General1
2026-07-171
Active Exploitation1
Full discourse3 posts
  • Yusuf Can Çakır@Yusufcancakiir
    Active Exploitation

    Found an open directory hosting a layered financial fraud operation across three simultaneous tracks: a Magecart-style card skimmer chain, a mass CVE exploitation framework, and a trojan distributed through Chinese streaming software packaging. All of it feeding the same PII collection pipeline. The skimmer track starts with FOFA. The actor runs automated queries targeting WooCommerce, Magento, and Stripe-integrated checkout pages, sorting results into structured target lists by category: builder_woo_checkout, stripe_woo_checkout, magento_checkout, checkout_cdn_js. Output lands in pii_consolidated.csv, with a second batch file visible alongside it. This has been running in passes. The skimmer component is a WooCommerce and Stripe-targeted Magecart payload. Injection engine supports page-level download, mitmproxy transparent proxy, and browser console delivery. C2 receiver runs on the same host. Target profile: Stripe Elements checkout pages, WooCommerce wc-ajax endpoints. The exploitation track runs in parallel. poc_scanner.py drives 300 concurrent probes against FOFA-sourced targets through a three-stage pipeline: liveness check, service fingerprinting, then PoC verification. CVEs being actively weaponized: CVE-2026-21858 — n8n unauthenticated RCE, CVSS 10.0 CVE-2026-6815 — Casdoor path traversal to RCE, CVSS 9.8 CVE-2026-32604 — Spinnaker shell injection, CVSS 10.0 CVE-2026-34486 — Tomcat Tribes auth bypass to RCE, CVSS 9.8 CVE-2026-25212 — Percona PMM RCE, CVSS 9.9 CVE-2026-35273 — PeopleSoft unauthenticated SSRF to RCE, CVSS 9.8 CVE-2026-23744 — MCPJam Inspector unauthenticated RCE, CVSS 9.8 CVE-2026-42167 — ProFTPD CVE-2026-6182 — SQL injection auth bypass CVE-2025-24587, CVE-2025-4396 A separate WordPress track runs alongside: mass SQL injection via wp_sqli_mass.py, aggressive dump via wp_aggressive_dump.py, PhpMyAdmin brute-force against the same pool. The trojan track is socially engineered. 直播助手化.v2.exe presents as a legitimate Chinese streaming helper application. VMProtect 3.2–3.5 wrapping. 29/70 on VirusTotal at time of analysis. Family: flystudio, chinad, dlii. It ships with HPSocket4C.dll, pb.dll, pb64.dll, and gzip.dll as side-loaded components. The infection surface is Chinese-speaking streaming users who would recognize the product name as familiar tooling. C2 routes through v2ray. Two license spoofing servers complete the toolkit. bypass_server.py impersonates http://premium.dotbypasser.workers.dev, handling RSA-OAEP encrypted license exchange and returning forged validation responses with 10-year expiry timestamps. fake_auth_server.py covers a separate streaming platform, impersonating http://api.vmks.cn and related domains, returning fake authorization tokens. Both appear to serve tooling distribution rather than direct victim infrastructure. One additional finding on the C2 host: evidence of AI-assisted offensive operations. A DeepSeek API configuration points to http://api.deepseek.com through an Anthropic-compatible interface, and a structured offensive security framework containing 70+ purpose-built skill modules for vulnerability classes including SQLi, XSS, SSRF, RCE, IDOR, OAuth, SAML, cloud misconfiguration, Kubernetes, CI/CD, M365/Entra, VMware vCenter, and supply chain recon. The actor is running systematized, AI-assisted attack methodology. This pattern is increasingly documented across financially motivated operations. OPSEC failure on an otherwise capable operator. filter_cn.py is on the box and actively used. It strips Chinese IP ranges from FOFA output sets before exploitation runs begin. The actor is deliberately skipping domestic targets, a consistent behavioral marker across Chinese financially motivated operations. Additionally, the FOFA API credential is hardcoded in cleartext across the client scripts. Easy attribution anchor.

    Post summary

    The passage details a sophisticated operation that actively scans and weaponizes multiple high‑severity CVEs for exploitation across e‑commerce, WordPress, and trojan channels, indicating ongoing real‑world attacks.

    215054404.8K
    1.6K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6815 An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with admi… https://www.cve.org/CVERecord?id=CVE-2026-6815

    Post summary

    The post announces CVE‑2026‑6815 as an arbitrary file write flaw with basic technical details, but lacks any PoC, exploit, patch, or exploitation evidence.

    00000104
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6815 Arbitrary File Write via Path Traversal in Casdoor Local F... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6815 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    CVE-2026-6815 is disclosed as an arbitrary file write vulnerability via path traversal in Casdoor, with no evidence of active exploitation, patch, or PoC details provided.

    0000040
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcasbincasdoor---

Explore more