CVE-2026-97737
7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Summary
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| muety | Wakapi | 0 < 2.17.6 | affected |
Weaknesses
- CWE-843: CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')
Workarounds
Disable user caching
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://github.com/muety/wakapi/security/advisories/GHSA-x48w-3rq3-w2pq
- https://github.com/muety/wakapi/releases/tag/2.17.6
- https://github.com/muety/wakapi/commit/ce91eac2c2d9b29a00873554d2ecef76f10b9087
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.