


Perceptive Security
SOC/SIEM Consultancy

Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independently without …
Published:
30 juli 2026 om 00:00:00
Alert date:
30 juli 2026 om 17:06:28
Source:
nvd.nist.gov
Web Technologies, Identity & Access
Serendipity versions before 2.6.1 contain an authentication context confusion vulnerability tracked as CVE-2026-67351. The flaw arises because password validation and session loading operate independently without ensuring they reference the same user record. An authenticated Editor-level user can exploit this by creating a username collision with an Administrator account. Upon login, the Editor's password is validated against their own record, but the session loads the Administrator's account data. This results in the attacker obtaining full administrative privileges. The vulnerability represents a logic flaw in the authentication pipeline rather than a traditional credential theft. A patch is available in Serendipity 2.6.1. The issue has been documented in GitHub Security Advisories and VulnCheck.
Technical details
Mitigation steps:
Affected products:
Serendipity
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67351
https://github.com/s9y/Serendipity/security/advisories/GHSA-v645-243f-jwgh
https://www.vulncheck.com/advisories/serendipity-authentication-bypass-via-username-collision
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
