SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77337

CRITICAL · CVSS 9.1 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The CakePHP Authentication plugin is vulnerable to authentication bypass and potential CPU or memory exhaustion due to the use of unencrypted, forgeable legacy tokens in versions prior to 2.11.2, 3.0.0 through 3.3.6, and 4.0.0 through 4.2.0. This critical vulnerability can compromise application security and lead to resource exhaustion, making it imperative for developers and system administrators using affected versions to prioritize upgrading to the patched releases 2.11.2, 3.3.7, or 4.2.1.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77337
Severity
CRITICAL
CVSS
9.1
EPSS
0.39%

Original NVD Description

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.