Webhook Vulnerability in Wallos Open-Source Subscription Tracker by Ellite
CVE-2026-41689

6MEDIUM

Key Information:

Vendor

Ellite

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-41689?

Wallos, an open-source personal subscription tracker, has a vulnerability in its webhook notification feature. In versions 4.8.4 and earlier, the allowlist configuration set by administrators is incorrectly reused for all logged-in users. This imperfection allows any authenticated user to gain full control over webhook URLs, headers, and body. As a result, users can send unauthorized server-side requests to internal automation services that are included in the allowlist. If these services expose configuration or execution APIs, it could potentially lead to further remote code execution, depending on the exposed service. There are currently no patches available to address this vulnerability.

Affected Version(s)

Wallos <= 4.8.4

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.