Looking for the vulnerability index of Invicti's legacy products?
CakePHP URL Redirection to Untrusted Site (Open Redirect) Vulnerability - CVE-2026-55590 - Vulnerability Database

CakePHP URL Redirection to Untrusted Site (Open Redirect) Vulnerability - CVE-2026-55590

Medium
Reference: CVE-2026-55590
Title: CakePHP URL Redirection to Untrusted Site (Open Redirect) Vulnerability
Overview:

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1 3.3.6 and 4.1.1 the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue is fixed in versions 2.11.1 3.3.6 and 4.1.1.