Description
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to version 2.17.6 or later
Vendor Workaround
Disable user caching
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 25 Sep 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover. | |
| Weaknesses | CWE-843 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-25T04:08:25.094Z
Reserved: 2026-09-25T04:08:24.297Z
Link: CVE-2026-97737
No data.
Status : Received
Published: 2026-09-25T05:17:07.760
Modified: 2026-09-25T05:17:07.760
Link: CVE-2026-97737
No data.
OpenCVE Enrichment
No data.
Weaknesses
