CVE-2026-77337
CakePHP: Potential Authentication bypass with CookieAuthenticator
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.
| CWE | CWE-290 CWE-770 |
| Vendor | cakephp |
| Product | authentication |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for cakephp authentication
Be the first to know when new unknown vulnerabilities affecting cakephp authentication are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
cakephp / authentication
< 2.11.2 >= 3.0.0, < 3.3.7 >= 4.0.0, < 4.2.1
References
github.com: https://github.com/cakephp/authentication/security/advisories/GHSA-h7xh-9h2x-2m37 github.com: https://github.com/cakephp/authentication/pull/806 github.com: https://github.com/cakephp/authentication/pull/807 github.com: https://github.com/cakephp/authentication/commit/c94d9a5380e7f4fdf38d338a9de2223a5b087159