CVE-2026-97737

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-25: 109-25
Full discourse1 post
  • CyberSignal | Cybersecurity & AI News@XQOPTRX

    🚨 POST 30 — WAKAPI ACCOUNT-TAKEOVER VULNERABILITY DISCLOSED TODAY Another newly published vulnerability affects Wakapi, the self-hosted coding-time tracking platform. Tracked as: CVE-2026-97737 CVSS: 7.4 HIGH Affected: Wakapi versions before 2.17.6 when user caching is enabled. The issue involves Wakapi's user caching service resolving a lookup in an unintended context. Under the vulnerable configuration, the flaw can lead to account takeover. Notable properties: 🌐 Network exploitable 🔑 No existing privileges required 🖱️ No user interaction required The project has released Wakapi 2.17.6 to fix the issue. A workaround is also available: disable user caching. 🛡️ Organizations running Wakapi should upgrade to 2.17.6 or later. Sources: MITRE CVE record · GitHub Security Advisory · OpenCVE.

    0102055
    228 followersView on X

Explore more