Authentication Bypass in Wallos Personal Subscription Tracker by Ellite
CVE-2026-54600
8.2HIGH
What is CVE-2026-54600?
Wallos, an open-source personal subscription tracker, prior to version 4.9.4, contains a serious authentication bypass vulnerability. The flaw exists in the endpoints/db/import.php file, where authentication measures are inadequate. Specifically, a user-table row count serves as the only line of defense, which is ineffective if the count is zero due to a fresh or unconfigured installation. This vulnerability permits an unauthenticated attacker to replace the entire database, compromising user data and system integrity. The issue has been rectified in version 4.9.4.
Affected Version(s)
Wallos < 4.9.4
