PT-2026-98352 · Wakapi · Wakapi

CVE-2026-97737

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Wakapi versions prior to 2.17.6
Description The user caching service allows a lookup to be resolved in an unintended lookup context. This flaw occurs when user caching is enabled and can lead to account takeover.
Recommendations Update to version 2.17.6 or later. Disable user caching as a temporary workaround.

Exploit

Fix

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97737
GHSA-X48W-3RQ3-W2PQ

Affected Products

Wakapi