CVE-2026-97737: Muety Wakapi

High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.

In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.

Affected products

  • Muety Wakapi: before 2.17.6 (fixed in 2.17.6)

Published 2026-09-25. Last modified 2026-09-30.