Authentication Bypass in Wallos Personal Subscription Tracker by Ellite
CVE-2026-54600

8.2HIGH

Key Information:

Vendor

Ellite

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-54600?

Wallos, an open-source personal subscription tracker, prior to version 4.9.4, contains a serious authentication bypass vulnerability. The flaw exists in the endpoints/db/import.php file, where authentication measures are inadequate. Specifically, a user-table row count serves as the only line of defense, which is ineffective if the count is zero due to a fresh or unconfigured installation. This vulnerability permits an unauthenticated attacker to replace the entire database, compromising user data and system integrity. The issue has been rectified in version 4.9.4.

Affected Version(s)

Wallos < 4.9.4

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.