CVE-2026-67351

Serendipity < 2.6.1 Authentication Bypass via Username Collision

Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independently without ensuring both use the same user record. An authenticated Editor can create a username collision with an Administrator account and obtain administrative privileges by logging in with their own password while the session loads the Administrator's account data.


We have discovered 598 live websites that are affected by CVE-2026-67351.

Run a Free Instant Scan




Affected Software

Product  Serendipity
Category Content Management System
Vulnerable Domains598 live websites (100% of Serendipity install base)
Vulnerable Versions
  • from 0 through 2.6.1
Vulnerable Versions Count40 versions ( 100% of all versions)



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Vaibhav Kubade (@DevVaibhav07) (finder)

Website Distribution by Country

Number of websites using CVE-2026-67351
United States107 websites



Germany343 websites
Netherlands23 websites
Switzerland18 websites
GB14 websites
France12 websites
Italy7 websites
Austria6 websites
Australia6 websites
Canada6 websites

Website Distribution by TLD

Number of websites using CVE-2026-67351
.de257 websites
.com122 websites
.net55 websites
.org43 websites
.ch16 websites
.info16 websites
.nl11 websites
.co.uk10 websites
.at7 websites
.ca5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-67351

Top websites that are affected by CVE-2026-67351. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.**********.de United States***,***
****.***************.org Germany***,***
**************.com United States***,***
*********.com United States***,***
*********.de Germany***,***
****.******.de Germany***,***
***************************.de Germany***,***
***********.de Germany***,***
***********.de Germany***,***
*****.net United States***,***
See full domain list

FAQ

A total of 598 websites have been identified as vulnerable to CVE-2026-67351, based on global website indexing conducted by WebTechSurvey.
The Serendipity is affected by the CVE-2026-67351 vulnerability.
Serendipity versions up to 2.6.1 are vulnerable to CVE-2026-67351.
CVE-2026-67351 is resolved in version 2.6.1 of Serendipity.