PT-2026-98352 · Wakapi · Wakapi
CVE-2026-97737
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Wakapi versions prior to 2.17.6
Description
The user caching service allows a lookup to be resolved in an unintended lookup context. This flaw occurs when user caching is enabled and can lead to account takeover.
Recommendations
Update to version 2.17.6 or later.
Disable user caching as a temporary workaround.
Exploit
Fix
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wakapi