Authentication Context Confusion Vulnerability in Serendipity by s9y
CVE-2026-67351

8.7HIGH

Key Information:

Vendor

S9y

Vendor
CVE Published:
30 July 2026

What is CVE-2026-67351?

The vulnerability in Serendipity prior to version 2.6.1 allows for a confusing authentication context where password validation and session loading function independently. This can lead to an environment where an authenticated Editor can exploit a username collision with an Administrator's account. Through this exploit, the Editor could log in with their own password while the session initializes with the Administrator's account information. This flaw undermines the integrity of user sessions and can potentially grant unauthorized administrative privileges, posing a significant security risk.

Affected Version(s)

Serendipity 0 < 2.6.1

Serendipity 2.6.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vaibhav Kubade (@DevVaibhav07)
.