CVE-2026-55590: Cakephp
Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue is fixed in versions 2.11.1, 3.3.6, and 4.1.1.
Affected products
- Cakephp Cakephp: before 2.11.1 (fixed in 2.11.1); from 3.0.0, before 3.3.6 (fixed in 3.3.6); from 4.0.0, before 4.1.1 (fixed in 4.1.1)
Published 2026-07-09. Last modified 2026-07-13.