Webhook Vulnerability in Wallos Open-Source Subscription Tracker by Ellite
CVE-2026-41689
6MEDIUM
What is CVE-2026-41689?
Wallos, an open-source personal subscription tracker, has a vulnerability in its webhook notification feature. In versions 4.8.4 and earlier, the allowlist configuration set by administrators is incorrectly reused for all logged-in users. This imperfection allows any authenticated user to gain full control over webhook URLs, headers, and body. As a result, users can send unauthorized server-side requests to internal automation services that are included in the allowlist. If these services expose configuration or execution APIs, it could potentially lead to further remote code execution, depending on the exposed service. There are currently no patches available to address this vulnerability.
Affected Version(s)
Wallos <= 4.8.4
