Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notification feature reuses an administrator-configured local-target allowlist for every logged-in user. Any normal user can fully control a webhook URL, headers, and body, then use Wallos to send server-side requests to allowlisted internal automation services. When such a target exposes deployment or execution APIs, this can further enable adjacent-service RCE, but that downstream result is conditional on the target service. At time of publication, there are no publicly available patches.
References
Configurations
No configuration.
History
07 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-07 15:16
Updated : 2026-05-07 16:16
NVD link : CVE-2026-41689
Mitre link : CVE-2026-41689
CVE.ORG link : CVE-2026-41689
JSON object : View
Products Affected
No product.
