CRITICAL
9.8 CVE-2026-85181 Published 3 Sept 2026
CAT Session Cookie Forgery Vulnerability
Worried this affects one of your servers?
CAT, a web application framework, uses Java String.hashCode as the sole integrity check for session cookies.
This allows attackers to forge valid checksums offline, creating admin sessions with full configuration access.
Attackers can also bypass IP binding validation by setting the x-forwarded-for header.
Reference: CVE-2026-85181 on NVD
← Back to Security News