Flip your way to admin — without the key

A server issues a session token as unauthenticated AES-CBC ciphertext — base64(IV ‖ C0 ‖ C1), no MAC, no auth tag. You've intercepted one token (the key is never sent). Can you turn role=guest into role=admin by editing ciphertext bytes you can't even decrypt — without ever learning the key?

The intercepted token (this is all an attacker ever sees on the wire) — plus a tag standing in for whatever real integrity check an AEAD-mode twin of this app would attach (GCM's own tag math is different, but "no key, no valid tag" holds either way):

What you compute (never touching the key):

Forged token you'd replay as your cookie

Verifier A — AES-CBC, no MAC (like :8096)

decrypt(token), then read the field at its fixed byte offset

Verifier B — AEAD, e.g. AES-GCM (like :8097)

reject before trusting the plaintext unless the tag matches (GCM checks this over its own CTR-mode ciphertext — a different mode from CBC, same "no key, no tag" idea)