Junglewise Threat Intelligence

CVE-2026-77337: CakePHP Authentication plugin authentication bypass via legacy tokens

CVE-2026-77337 · Severity: info · CVSS 0 · Published 2026-08-24

Vendors: Cakephp.

Executive brief

CakePHP Authentication is a plugin that manages user login and session verification for CakePHP web applications. Versions before the fix allow attackers to forge authentication cookies and gain unauthorized access to user accounts, or cause the application to exhaust CPU and memory resources through crafted requests. This could lead to account takeover, data exposure, or service outages.

Technical details

The vulnerability resides in the CookieAuthenticator component, which in affected versions stores user authentication tokens in unencrypted, unsigned cookies that are easily forgeable. An attacker can craft valid authentication cookies without knowing legitimate user credentials, bypassing authentication. Additionally, the legacy token mechanism is susceptible to resource exhaustion attacks that can consume CPU and memory. The vulnerability affects versions before 2.11.2, 3.0.0 through 3.3.6, and 4.0.0 through 4.2.0. The fix replaces unencrypted tokens with HMAC-SHA256 verified tokens. The attack requires network access to the affected application but no prior authentication or user interaction.

Affected products

  • CakePHP Authentication before 2.11.2, 3.0.0 through 3.3.6, 4.0.0 through 4.2.0

Timeline

  • 2026-08-24: disclosed
  • 2026-07-04: patched: Fix released in versions 2.11.2, 3.3.7, and 4.2.1

References