CVE-2026-77337

critical

Description

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.

References

https://github.com/cakephp/authentication/security/advisories/GHSA-h7xh-9h2x-2m37

https://github.com/cakephp/authentication/pull/807

https://github.com/cakephp/authentication/pull/806

https://github.com/cakephp/authentication/commit/c94d9a5380e7f4fdf38d338a9de2223a5b087159

Details

Source: Mitre, NVD

Published: 2026-08-24

Updated: 2026-08-24

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

CVSS v4

Base Score: 9.1

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Severity: Critical