top of page
perceptive_background_267k.jpg

Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independently without …

Published:

30 juli 2026 om 00:00:00

Alert date:

30 juli 2026 om 17:06:28

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

Serendipity versions before 2.6.1 contain an authentication context confusion vulnerability tracked as CVE-2026-67351. The flaw arises because password validation and session loading operate independently without ensuring they reference the same user record. An authenticated Editor-level user can exploit this by creating a username collision with an Administrator account. Upon login, the Editor's password is validated against their own record, but the session loads the Administrator's account data. This results in the attacker obtaining full administrative privileges. The vulnerability represents a logic flaw in the authentication pipeline rather than a traditional credential theft. A patch is available in Serendipity 2.6.1. The issue has been documented in GitHub Security Advisories and VulnCheck.

Technical details

Mitigation steps:

Affected products:

Serendipity

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page