CVE-2026-77337

Source
https://cve.org/CVERecord?id=CVE-2026-77337
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77337.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-77337
Aliases
  • GHSA-h7xh-9h2x-2m37
Downstream
Published
2026-08-24T21:30:06.817Z
Modified
2026-08-27T11:47:36.670235795Z
Severity
  • 9.1 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
CakePHP: Potential Authentication bypass with CookieAuthenticator
Details

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77337.json",
    "cwe_ids": [
        "CWE-290",
        "CWE-770"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/cakephp/authentication

Affected ranges

Type
GIT
Repo
https://github.com/cakephp/authentication
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.11.2"
        },
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.3.7"
        },
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.2.1"
        }
    ]
}

Affected versions

1.*
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.0-beta3
1.0.0-beta4
1.0.0-rc1
1.0.0-rc2
1.0.0-rc3
1.0.0-rc4
1.0.0-rc5
1.0.0-rc6
1.0.0-rc7
1.0.0-rc8
1.0.0-rc9
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
1.2.1
1.3.0
1.4.0
2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.10.0
2.11.0
2.11.1
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.7.0
2.8.0
2.9.0
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.2.0
3.2.1
3.2.2
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
4.*
4.0.0
4.0.1
4.1.0
4.1.1
4.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77337.json"