


Perceptive Security
SOC/SIEM Consultancy

Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independently without …
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 15:06:28
Source:
nvd.nist.gov
Web Technologies, Identity & Access
Serendipity versions before 2.6.1 contain an authentication context confusion vulnerability tracked as CVE-2026-67351. The flaw arises because password validation and session loading operate independently without ensuring they reference the same user record. An authenticated Editor-level user can exploit this by creating a username collision with an Administrator account. Upon login, the Editor's password is validated against their own record, but the session loads the Administrator's account data. This results in the attacker obtaining full administrative privileges. The vulnerability represents a logic flaw in the authentication pipeline rather than a traditional credential theft. A patch is available in Serendipity 2.6.1. The issue has been documented in GitHub Security Advisories and VulnCheck.
Technical details
Mitigation steps:
Affected products:
Serendipity
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67351
https://github.com/s9y/Serendipity/security/advisories/GHSA-v645-243f-jwgh
https://www.vulncheck.com/advisories/serendipity-authentication-bypass-via-username-collision
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
