๐Ÿ” CVE Alert

CVE-2026-77337

UNKNOWN 0.0

CakePHP: Potential Authentication bypass with CookieAuthenticator

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.

CWE CWE-290 CWE-770
Vendor cakephp
Product authentication
Published Aug 24, 2026
Stay Ahead of the Next One

Get instant alerts for cakephp authentication

Be the first to know when new unknown vulnerabilities affecting cakephp authentication are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

cakephp / authentication
< 2.11.2 >= 3.0.0, < 3.3.7 >= 4.0.0, < 4.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cakephp/authentication/security/advisories/GHSA-h7xh-9h2x-2m37 github.com: https://github.com/cakephp/authentication/pull/806 github.com: https://github.com/cakephp/authentication/pull/807 github.com: https://github.com/cakephp/authentication/commit/c94d9a5380e7f4fdf38d338a9de2223a5b087159