CVE-2026-77337
Received Received - Intake

Authentication Bypass in CakePHP via Legacy Tokens

Vulnerability report for CVE-2026-77337, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: GitHub, Inc.

Description

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
cakephp cakephp_authentication to 2.11.2 (exc)
cakephp cakephp_authentication From 3.0.0 (inc) to 3.3.6 (inc)
cakephp cakephp_authentication From 4.0.0 (inc) to 4.2.0 (inc)
cakephp cakephp_authentication 2.11.2
cakephp cakephp_authentication 3.3.7
cakephp cakephp_authentication 4.2.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CakePHP Authentication plugin versions before 2.11.2, 3.0.0-3.3.6, and 4.0.0-4.2.0 have an authentication bypass flaw. It allows attackers to forge legacy tokens when CookieAuthenticator uses unencrypted tokens, leading to unauthorized access. This can also cause CPU or memory exhaustion due to improper token handling.

Impact Analysis

If you use affected CakePHP Authentication versions, attackers could bypass authentication to gain unauthorized access to your application. This may lead to data breaches, privilege escalation, or denial-of-service conditions due to resource exhaustion.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR (data protection) and HIPAA (health data security) requirements. Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Update CakePHP Authentication plugin to versions 2.11.2, 3.3.7, or 4.2.1 or later to address the authentication bypass and resource exhaustion issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77337. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart