Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-77337: CakePHP Authentication can be bypassed or overloaded
CVE-2026-77337 · published 1 month ago
Summary
If you are using the CakePHP Authentication plugin in versions before 2.11.2, 3.3.7, or 4.2.1, an attacker could trick the system into accepting fake login cookies and could also cause the server to use excessive CPU or memory. Update the plugin to the latest version to close these gaps and protect logins and performance.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | cakephp | authentication | < 2.11.2 |
| Debian:11 | debian | cakephp | All versions |
Original advisory text
CakePHP: Potential Authentication bypass with CookieAuthenticator
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.
References
- https://github.com/cakephp/authentication/commit/c94d9a5380e7f4fdf38d338a9de2223...
- https://github.com/cakephp/authentication/pull/806
- https://github.com/cakephp/authentication/pull/807
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77337... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-77337 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-77337 Vendor Advisory
- https://github.com/cakephp/authentication/security/advisories/GHSA-h7xh-9h2x-2m3...
Severity
9.1
Critical
CVSS 4.0: 9.1 (OSV)
CVSS 4.0: 9.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-290Authentication Bypass by Spoofing
CWE-770Allocation of Resources Without Limits
Timeline
Published24 Aug 2026
Updated27 Sep 2026
First seen24 Aug 2026
Sources
CVE-2026-77337 · NVD
CVE-2026-77337 · MITRE
DEBIAN-CVE-2026-77337 · OSV
CVE-2026-77337 · OSV
GHSA-h7xh-9h2x-2m37 · GHSA
Track software like this
Free during beta