What is CVE-2026-67351?
CVE-2026-67351 is an authentication context confusion vulnerability in Serendipity versions before 2.6.1. An authenticated Editor can exploit a username collision with an Administrator account to gain administrative privileges. It is recommended to upgrade to Serendipity version 2.6.1 or later immediately.
Azərbaycanca: CVE-2026-67351 Serendipity-nin 2.6.1-dən əvvəlki versiyalarında autentifikasiya konteksti qarışıqlığı (authentication context confusion) zəifliyidir. Autentifikasiya olunmuş Editor istifadəçisi Administrator hesabı ilə istifadəçi adı toqquşması (username collision) yaradaraq admin səlahiyyətləri əldə edə bilər. Dərhal Serendipity-ni 2.6.1 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What level of account must an attacker have to exploit CVE-2026-67351?
The attacker must have an authenticated Editor user account.
What action is recommended to mitigate CVE-2026-67351?
It is recommended to upgrade to Serendipity version 2.6.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.