Authentication Context Confusion Vulnerability in Serendipity by s9y
CVE-2026-67351
8.7HIGH
What is CVE-2026-67351?
The vulnerability in Serendipity prior to version 2.6.1 allows for a confusing authentication context where password validation and session loading function independently. This can lead to an environment where an authenticated Editor can exploit a username collision with an Administrator's account. Through this exploit, the Editor could log in with their own password while the session initializes with the Administrator's account information. This flaw undermines the integrity of user sessions and can potentially grant unauthorized administrative privileges, posing a significant security risk.
Affected Version(s)
Serendipity 0 < 2.6.1
Serendipity 2.6.1
