Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-77337: CakePHP Authentication can be bypassed or overloaded

CVE-2026-77337 · published 1 month ago
Summary

If you are using the CakePHP Authentication plugin in versions before 2.11.2, 3.3.7, or 4.2.1, an attacker could trick the system into accepting fake login cookies and could also cause the server to use excessive CPU or memory. Update the plugin to the latest version to close these gaps and protect logins and performance.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
– cakephp authentication < 2.11.2
Debian:11 debian cakephp All versions
Original advisory text
CakePHP: Potential Authentication bypass with CookieAuthenticator
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.
Severity
9.1 Critical
CVSS 4.0: 9.1 (OSV)
CVSS 4.0: 9.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-290Authentication Bypass by Spoofing
CWE-770Allocation of Resources Without Limits
Timeline
Published24 Aug 2026
Updated27 Sep 2026
First seen24 Aug 2026
Track software like this
Free during beta