{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cat/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cat_project:cat:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85181"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CAT"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe CAT application suffers from a critical vulnerability (CVE-2026-85181) where session cookie integrity is verified using only the Java String.hashCode method without a server-side secret key. Because hashCode is a deterministic, non-cryptographic function, an attacker can perform offline computation to generate valid checksums for arbitrary session cookies. By manipulating the cookie content, attackers can escalate privileges to an administrative role. Additionally, the application improperly relies on the 'x-forwarded-for' HTTP header to enforce IP-based access controls, allowing attackers to spoof client IPs and bypass secondary security mechanisms. This combination of flaws enables full, unauthenticated takeover of the application configuration and data.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to forge session cookies, granting them full administrative access to the CAT application. This leads to complete compromise of the system configuration, potential data exfiltration, and full control over application functionality. Given the CVSS score of 9.8, this vulnerability represents a critical risk for any environment exposing CAT to an untrusted network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate update or patching of the CAT application as soon as the vendor provides a secure implementation replacing String.hashCode with a cryptographically secure message authentication code (HMAC). Until a patch is applied, implement strict egress/ingress filtering at the web application firewall (WAF) to block requests that manipulate the 'x-forwarded-for' header from untrusted sources. Audit all administrative sessions for anomalous patterns, specifically looking for session cookies that were not preceded by a standard authentication flow (e.g., POST to /login).\u003c/p\u003e\n","date_modified":"2026-09-03T15:21:31Z","date_published":"2026-09-03T15:21:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cat-session-forgery/","summary":"The CAT application relies on the predictable Java String.hashCode method for session cookie integrity, allowing attackers to forge administrative sessions by bypassing weak IP validation.","title":"Unauthenticated Session Forgery and Privilege Escalation in CAT","url":"https://feed.craftedsignal.io/briefs/2026-09-cat-session-forgery/"}],"language":"en","title":"CraftedSignal Threat Feed - CAT","version":"https://jsonfeed.org/version/1.1"}