
🚨 POST 30 — WAKAPI ACCOUNT-TAKEOVER VULNERABILITY DISCLOSED TODAY Another newly published vulnerability affects Wakapi, the self-hosted coding-time tracking platform. Tracked as: CVE-2026-97737 CVSS: 7.4 HIGH Affected: Wakapi versions before 2.17.6 when user caching is enabled. The issue involves Wakapi's user caching service resolving a lookup in an unintended context. Under the vulnerable configuration, the flaw can lead to account takeover. Notable properties: 🌐 Network exploitable 🔑 No existing privileges required 🖱️ No user interaction required The project has released Wakapi 2.17.6 to fix the issue. A workaround is also available: disable user caching. 🛡️ Organizations running Wakapi should upgrade to 2.17.6 or later. Sources: MITRE CVE record · GitHub Security Advisory · OpenCVE.
