---
id: CVE-2026-77337
title: >-
  CakePHP Authentication is an authentication plugin for CakePHP that can also
  be used in PSR-7 based applications
summary: >-
  CakePHP Authentication is an authentication plugin for CakePHP that can also
  be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0
  through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and
  potential CP…
severity: none
cwe:
  - CWE-290
  - CWE-770
published: '2026-08-24'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:07:31.353'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77337'
references:
  - url: >-
      https://github.com/cakephp/authentication/commit/c94d9a5380e7f4fdf38d338a9de2223a5b087159
    label: security-advisories@github.com
  - url: 'https://github.com/cakephp/authentication/pull/806'
    label: security-advisories@github.com
  - url: 'https://github.com/cakephp/authentication/pull/807'
    label: security-advisories@github.com
  - url: >-
      https://github.com/cakephp/authentication/security/advisories/GHSA-h7xh-9h2x-2m37
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00389
epssPercentile: 0.32849
ingestedAt: '2026-09-09T21:22:45.549Z'
---

## Overview

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
