CVE Explorer
CVE-2026-55590
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue is fixed in versions 2.11.1, 3.3.6, and 4.1.1.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"authentication","vendor":"cakephp","versions":[{"status":"affected","version":"< 2.11.1"},{"status":"affected","version":">= 3.0.0, < 3.3.6"},{"status":"affected","version":">= 4.0.0, < 4.1.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a16e71d89aacc247bd0ccf65504d6f27bb351cf0abb58ba2b52b983e0c1ae570 · sha256:b8503d0f812ebbca… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.1,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"ACTIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a16e71d89aacc247bd0ccf65504d6f27bb351cf0abb58ba2b52b983e0c1ae570 · sha256:b8503d0f812ebbca… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-601","description":"CWE-601: URL Redirection to Untrusted Site ('Open Redirect')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a16e71d89aacc247bd0ccf65504d6f27bb351cf0abb58ba2b52b983e0c1ae570 · sha256:b8503d0f812ebbca… · /containers/cna/problemTypes/0/descriptions/0
Source references
10 source assertions{"name":"https://github.com/cakephp/authentication/commit/1c1e29c7e8129cfbcae74558316ecd3ea50a8273","tags":["x_refsource_MISC"],"url":"https://github.com/cakephp/authentication/commit/1c1e29c7e8129cfbcae74558316ecd3ea50a8273"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a16e71d89aacc247bd0ccf65504d6f27bb351cf0abb58ba2b52b983e0c1ae570 · sha256:b8503d0f812ebbca… · /containers/cna/references/4
{"name":"https://github.com/cakephp/authentication/commit/df28ea4e712f1e5bd0e42be4a3c5c750ca50764d","tags":["x_refsource_MISC"],"url":"https://github.com/cakephp/authentication/commit/df28ea4e712f1e5bd0e42be4a3c5c750ca50764d"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a16e71d89aacc247bd0ccf65504d6f27bb351cf0abb58ba2b52b983e0c1ae570 · sha256:b8503d0f812ebbca… · /containers/cna/references/5
{"name":"https://github.com/cakephp/authentication/commit/ee24bd48b9c3ef693dc9965de8f0cc8020a7052c","tags":["x_refsource_MISC"],"url":"https://github.com/cakephp/authentication/commit/ee24bd48b9c3ef693dc9965de8f0cc8020a7052c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a16e71d89aacc247bd0ccf65504d6f27bb351cf0abb58ba2b52b983e0c1ae570 · sha256:b8503d0f812ebbca… · /containers/cna/references/6
{"name":"https://github.com/cakephp/authentication/pull/795","tags":["x_refsource_MISC"],"url":"https://github.com/cakephp/authentication/pull/795"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a16e71d89aacc247bd0ccf65504d6f27bb351cf0abb58ba2b52b983e0c1ae570 · sha256:b8503d0f812ebbca… · /containers/cna/references/1
{"name":"https://github.com/cakephp/authentication/pull/796","tags":["x_refsource_MISC"],"url":"https://github.com/cakephp/authentication/pull/796"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a16e71d89aacc247bd0ccf65504d6f27bb351cf0abb58ba2b52b983e0c1ae570 · sha256:b8503d0f812ebbca… · /containers/cna/references/2
{"name":"https://github.com/cakephp/authentication/pull/799","tags":["x_refsource_MISC"],"url":"https://github.com/cakephp/authentication/pull/799"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a16e71d89aacc247bd0ccf65504d6f27bb351cf0abb58ba2b52b983e0c1ae570 · sha256:b8503d0f812ebbca… · /containers/cna/references/3
{"name":"https://github.com/cakephp/authentication/releases/tag/2.11.1","tags":["x_refsource_MISC"],"url":"https://github.com/cakephp/authentication/releases/tag/2.11.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a16e71d89aacc247bd0ccf65504d6f27bb351cf0abb58ba2b52b983e0c1ae570 · sha256:b8503d0f812ebbca… · /containers/cna/references/7
{"name":"https://github.com/cakephp/authentication/releases/tag/3.3.6","tags":["x_refsource_MISC"],"url":"https://github.com/cakephp/authentication/releases/tag/3.3.6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a16e71d89aacc247bd0ccf65504d6f27bb351cf0abb58ba2b52b983e0c1ae570 · sha256:b8503d0f812ebbca… · /containers/cna/references/8
{"name":"https://github.com/cakephp/authentication/releases/tag/4.1.1","tags":["x_refsource_MISC"],"url":"https://github.com/cakephp/authentication/releases/tag/4.1.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a16e71d89aacc247bd0ccf65504d6f27bb351cf0abb58ba2b52b983e0c1ae570 · sha256:b8503d0f812ebbca… · /containers/cna/references/9
{"name":"https://github.com/cakephp/authentication/security/advisories/GHSA-hhpq-7wg4-36jm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/cakephp/authentication/security/advisories/GHSA-hhpq-7wg4-36jm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a16e71d89aacc247bd0ccf65504d6f27bb351cf0abb58ba2b52b983e0c1ae570 · sha256:b8503d0f812ebbca… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.