CVE-2026-85181

CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for header to bypass IP binding validation and create admin sessions with full configuration access.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 15:17

Updated : 2026-09-03 18:17


NVD link : CVE-2026-85181

Mitre link : CVE-2026-85181

CVE.ORG link : CVE-2026-85181


JSON object : View

Products Affected

No product.

CWE
CWE-565

Reliance on Cookies without Validation and Integrity Checking