CVE-2026-55590
EUVD-2026-4267409.07.2026, 19:17
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue is fixed in versions 2.11.1, 3.3.6, and 4.1.1.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cakephp | cakephp | 𝑥 < 2.11.1 |
| cakephp | cakephp | 3.0.0 ≤ 𝑥 < 3.3.6 |
| cakephp | cakephp | 4.0.0 ≤ 𝑥 < 4.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References