A server issues a session token as unauthenticated AES-CBC ciphertext —
base64(IV ‖ C0 ‖ C1), no MAC, no auth tag. You've intercepted one token (the key is
never sent). Can you turn role=guest into role=admin by editing
ciphertext bytes you can't even decrypt — without ever learning the key?
The intercepted token (this is all an attacker ever sees on the wire) — plus a tag standing in for whatever real integrity check an AEAD-mode twin of this app would attach (GCM's own tag math is different, but "no key, no valid tag" holds either way):
What you compute (never touching the key):
Forged token you'd replay as your cookie
:8096):8097)