CVE-2026-54713CWE-1023

CVE-2026-54713

Low · published August 28, 2026

CVSS v3.1
3.7
EPSS
0%
Percentile
29.4
In the wild
Unconfirmed
What it is

CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting parameter values drops associative-array keys. An unauthenticated attacker who can influence job parameters can submit semantically different data that produces the same identifier, resulting in legitimate jobs dropped as duplicate collisions. This issue is fixed in version 2.3.1.

The record
Technical detail
CVSS v3.1
3.7 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0
Not supplied
EPSS
0.00364 · 29.4th percentile
Weakness
CWE-1023 · Incomplete Comparison with Missing Factors
Published
2026-08-28T00:17Z
References (4)
EPSS history
Timeline
  • 27 AUG 17:03Z
    CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions
    cvelistv5