Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independently without ensuring both use the same user record. An authenticated Editor can create a username collision with an Administrator account and obtain administrative privileges by logging in with their own password while the session loads the Administrator's account data. | |
| Title | Serendipity < 2.6.1 Authentication Bypass via Username Collision | |
| First Time appeared |
S9y
S9y serendipity |
|
| Weaknesses | CWE-304 | |
| CPEs | cpe:2.3:a:s9y:serendipity:*:*:*:*:*:*:*:* | |
| Vendors & Products |
S9y
S9y serendipity |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-30T13:57:51.756Z
Reserved: 2026-07-29T13:36:36.277Z
Link: CVE-2026-67351
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-304
Missing Critical Step in Authentication