CVE-2026-97737: Muety Wakapi
High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
Affected products
- Muety Wakapi: before 2.17.6 (fixed in 2.17.6)
Published 2026-09-25. Last modified 2026-09-30.