Intel

AIKIDO-2025-10653

cakephp/cakephp is vulnerable to Improper Authorization

Improper Authorization Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

50

Medium Risk

This Affects:

PHPcakephp/cakephp
3.2.6 - 5.2.7
Fixed in 5.2.8

TL;DR

Certain versions of CakePHP could incorrectly generate SQL when embedding a subquery that was already executed. This could cause access control conditions (WHERE clauses, bindings) to be lost or mishandled, leading to unauthorized data exposure or bypassing logic checks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

cakephp/cakephp is vulnerable to Improper Authorization in versions 3.2.6 - 5.2.7.

How to fix this

Upgrade cake/cakephp to the patch version. A patch for 4.X is currently unavailable.