In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to version 2.17.6 or later
Workaround
Disable user caching
References
History
Fri, 25 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Muety
Muety wakapi |
|
| Vendors & Products |
Muety
Muety wakapi |
Fri, 25 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Account takeover via unintended cache context in Wakapi |
Fri, 25 Sep 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover. | |
| Weaknesses | CWE-843 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-25T04:08:25.094Z
Reserved: 2026-09-25T04:08:24.297Z
Link: CVE-2026-97737
No data.
Status : Received
Published: 2026-09-25T05:17:07.760
Modified: 2026-09-25T05:17:07.760
Link: CVE-2026-97737
No data.
OpenCVE Enrichment
Updated: 2026-09-25T14:14:42Z
Weaknesses