CVE-2026-97737: High severity Wakapi Wakapi vulnerability
Published Sep 25, 2026
·Updated
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
Affected Software
1 affected component
Wakapi Wakapi<2.17.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wakapito a version that resolves this vulnerability.Fixed in 2.17.6
Event History
Sep 25, 2026
CVE Published
via MITRE·04:08 AM
Data Sourced
via MITRE·04:08 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Wakapi versions need remediation?
Wakapi versions before 2.17.6 are affected. Upgrade to version 2.17.6 or later.
2
Can this be exploited remotely without an existing account?
The vector is network-based and the listed privileges required are none, so an attacker does not need prior authentication. Exploitation has high attack complexity.
3
What is the likely impact if exploitation succeeds?
The issue can lead to account takeover. Confidentiality and integrity impacts are rated high, while availability impact is rated none.