Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 2.17.6 or later
Vendor Workaround
Disable user caching
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Account takeover via unintended cache context in Wakapi |
Fri, 25 Sep 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover. | |
| Weaknesses | CWE-843 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-25T04:08:25.094Z
Reserved: 2026-09-25T04:08:24.297Z
Link: CVE-2026-97737
No data.
Status : Received
Published: 2026-09-25T05:17:07.760
Modified: 2026-09-25T05:17:07.760
Link: CVE-2026-97737
No data.
OpenCVE Enrichment
Updated: 2026-09-25T08:15:17Z
-
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')