VU#889462: Casdoor authentication server is vulnerable to authorization bypass
Casdoor IAM versions 3.115.0 and earlier allow organization admins to bypass tenant isolation through inconsistent authorization checks, tracked as CVE-2026-15630.
CERT/CC published VU#889462 describing an authorization bypass in Casdoor, an open-source access management platform, affecting versions 3.115.0 and earlier. The flaw (CVE-2026-15630) stems from controllers ignoring the ?id= query parameter used for authorization decisions and acting on JSON body fields instead, letting a single-organization administrator perform unauthorized administrative actions against arbitrary organizations in multi-tenant deployments. Impact can escalate to complete tenant-isolation compromise and potential compromise of the entire Casdoor instance, including SSO/SAML disruption. No vendor patch is available because researchers could not reach Casdoor; mitigations include least privilege, MFA for admin accounts, and alerting on cross-organization administrative activity.
France investigates tax authority breach after hacker claims 600,000 victims
France's tax authority DGFiP confirmed hackers extracted data on individuals and businesses; a hacker claims more than 600,000 victims.
France's Economy Ministry said an attacker gained unauthorized access to DGFiP systems in late June by stealing or misusing someone's identity, viewed and extracted data, and was cut off after detection. A hacker using the alias ZeroBytes claimed via FrenchBreaches to have taken data on over 600,000 people, including names, tax identification numbers, emails, family circumstances and tax status; the claim is unverified. The DGFiP will notify affected individuals, report to France's data protection authority and file a criminal complaint. It follows other 2026 breaches at ANTS, the Education Ministry and the National Bank Accounts File.