๐Ÿ” CVE Alert

CVE-2026-54600

UNKNOWN 0.0

Wallos: Unauthenticated database replacement via import endpoint on fresh install

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count โ€” if zero (fresh/unconfigured install), an unauthenticated attacker can replace the entire database. This issue has been patched in version 4.9.4.

CWE CWE-287
Vendor ellite
Product wallos
Published Aug 31, 2026
Stay Ahead of the Next One

Get instant alerts for ellite wallos

Be the first to know when new unknown vulnerabilities affecting ellite wallos are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ellite / Wallos
< 4.9.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ellite/Wallos/security/advisories/GHSA-8wqc-r9j3-rv7m github.com: https://github.com/ellite/Wallos/releases/tag/v4.9.4