GitHub Security Advisory (GHSA-v645-243f-jwgh)Vendor advisory
https://github.com/s9y/Serendipity/security/advisories/GHSA-v645-243f-jwgh CVE-2026-67351
HIGH
Serendipity < 2.6.1 Authentication Bypass via Username Collision
Record summary
CVE-2026-67351 has a selected CVSS score of 8.7 (high).
Description
Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independently without ensuring both use the same user record. An authenticated Editor can create a username collision with an Administrator account and obtain administrative privileges by logging in with their own password while the session loads the Administrator's account data.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SerendipityBrowse s9y / SerendipityDefault status: unaffected | CVE List | Before 2.6.1 | affected |
| 2.6.1 | unaffected |
References
2vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/serendipity-authentication-bypass-via-username-collision