Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-55590

30
FAUCET Score

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue is fixed in versions 2.11.1, 3.3.6, and 4.1.1.

First published: Jul 9, 2026Last modified: Jul 9, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 2.11.1CPE matchmatch criteria
cpe:2.3:a:cakephp:cakephp:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.3.6CPE matchmatch criteria
cpe:2.3:a:cakephp:cakephp:*:*:*:*:*:*:*:*
>= 4.0.0, < 4.1.1CPE matchmatch criteria
cpe:2.3:a:cakephp:cakephp:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.1MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
19.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 20th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

composerpatch availablevia ghsa
Product: cakephp/authenticationFixed in: 3.3.6
composerpatch availablevia ghsa
Product: cakephp/authenticationFixed in: 4.1.1
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-hhpq-7wg4-36jmmedium

CakePHP Authentication: Open redirect weakness via backslash bypass

Jun 17, 2026

References

github.com / cakephp/authentication/commit/1c1e29c7e8129cfbcae74558316ecd3ea50a8273
Patch
github.com / cakephp/authentication/commit/df28ea4e712f1e5bd0e42be4a3c5c750ca50764d
Patch
github.com / cakephp/authentication/commit/ee24bd48b9c3ef693dc9965de8f0cc8020a7052c
Patch
github.com / cakephp/authentication/pull/795
Issue TrackingPatch
github.com / cakephp/authentication/pull/796
Issue TrackingPatch
github.com / cakephp/authentication/pull/799
Issue TrackingPatch
github.com / cakephp/authentication/releases/tag/2.11.1
Release Notes
github.com / cakephp/authentication/releases/tag/3.3.6
Release Notes
github.com / cakephp/authentication/releases/tag/4.1.1
Release Notes
github.com / cakephp/authentication/security/advisories/GHSA-hhpq-7wg4-36jm
Vendor Advisory