HIGH 7.4 NVD
CVE-2026-97737
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
References
- https://github.com/muety/wakapi/commit/ce91eac2c2d9b29a00873554d2ecef76f10b9087
- https://github.com/muety/wakapi/releases/tag/2.17.6
- https://github.com/muety/wakapi/security/advisories/GHSA-x48w-3rq3-w2pq
This high severity vulnerability with a CVSS score of 7.4 was published on 2026-09-25 via NVD.
vulnfeed aggregates 10851 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.