PT-2026-83986 · Wallos · Wallos

CVE-2026-50198

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.9.1
Description An authenticated user can modify an inactive subscription by setting the replacement subscription id variable to a subscription ID belonging to another user. Because the stats logic dereferences this foreign ID without proper user id scoping, an attacker can infer the monthly-normalized cost of a victim's subscription by observing changes in their own statistics output. This allows the exposure of derived financial metadata without revealing the full subscription object.
Recommendations Update to version 4.9.1.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50198
GHSA-HGGR-V8RM-C6JJ

Affected Products

Wallos