SSRF Vulnerability in Wallos Subscription Tracker Affects Multiple Versions
CVE-2026-61638

8.2HIGH

Key Information:

Vendor

Ellite

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-61638?

Wallos, an open-source personal subscription tracker, is affected by a Server-Side Request Forgery (SSRF) vulnerability due to inadequate validation of user input in the email notification endpoint. Prior to version 4.9.6, this endpoint did not properly validate the 'smtpaddress' and 'smtpport' parameters provided in POST requests. As a result, an authenticated user could exploit this weakness to send requests to internal network services or access cloud metadata, posing a significant risk to sensitive data. The issue has been addressed in version 4.9.6, where appropriate validations have been implemented to prevent such exploitation.

Affected Version(s)

Wallos < 4.9.6

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.