CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for header to bypass IP binding validation and create admin sessions with full configuration access.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dianping
Dianping cat |
|
| Vendors & Products |
Dianping
Dianping cat |
Thu, 03 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for header to bypass IP binding validation and create admin sessions with full configuration access. | |
| Title | CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum | |
| Weaknesses | CWE-565 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-03T14:12:19.751Z
Updated: 2026-09-03T17:23:25.045Z
Reserved: 2026-09-03T11:08:17.527Z
Link: CVE-2026-85181
Updated: 2026-09-03T15:03:45.838Z
Status : Received
Published: 2026-09-03T15:17:39.433
Modified: 2026-09-03T18:17:33.530
Link: CVE-2026-85181
No data.