Executive brief
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
Junglewise Threat Intelligence
CVE-2026-97737 · Severity: high · CVSS 7.4 · Published 2026-09-25
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.