Session Cookie Forgery in CAT by Dianping
CVE-2026-85181
9.3CRITICAL
What is CVE-2026-85181?
The vulnerability in CAT allows attackers to exploit an insufficient integrity check on session cookies, using Java String.hashCode without server-side keying. This enables them to forge valid checksums offline. Additionally, by manipulating the x-forwarded-for header, attackers can bypass IP binding validation, leading to the creation of unauthorized admin sessions with full access to configurations.
Affected Version(s)
cat 0 <= 3.1.0
