Vulnerability Description
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.
Related Weaknesses (CWE)
References
- https://github.com/cakephp/authentication/commit/c94d9a5380e7f4fdf38d338a9de2223
- https://github.com/cakephp/authentication/pull/806
- https://github.com/cakephp/authentication/pull/807
- https://github.com/cakephp/authentication/security/advisories/GHSA-h7xh-9h2x-2m3
FAQ
What is CVE-2026-77337?
CVE-2026-77337 is a documented vulnerability. CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow a...
How severe is CVE-2026-77337?
CVSS scoring is not yet available for CVE-2026-77337. Check NVD for updates.
Is there a patch for CVE-2026-77337?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.