Impact
The vulnerability in Serendipity prior to version 2.6.1 allows an authenticated Editor to create a username collision with an existing Administrator account. During login, password validation and session loading are performed independently, so the system can accept the Editor’s password while loading the Administrator’s session data. This results in a privilege escalation that grants administrative privileges to the attacker. The weakness corresponds to CWE‑304, an authentication context confusion flaw.
Affected Systems
The affected product is Serendipity (s9y:Serendipity). Any installation running a version earlier than 2.6.1 is vulnerable; all other versions are considered unaffected.
Risk and Exploitability
The CVSS score for this Serendipity vulnerability is 8.7, indicating high severity. However, the EPSS score of <1% shows a very low likelihood that it will be actively exploited, and the issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to already have editorial privileges and an existing Administrator account, so the attack vector is limited to environments where credentials can be compromised or usernames are not strictly unique. The flaw does not involve arbitrary code execution; the attacker gains administrative functions, creating a significant threat to confidentiality, integrity, and availability if exploited. The overall risk remains low due to the low exploitation probability, but protective measures are still recommended.
OpenCVE Enrichment