CVE-2026-91998: casdoor: Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers… | Rapid7 Vulnerability Database