PT-2026-83989 · Wallos · Wallos

CVE-2026-54599

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v4.0

7.5

High

VectorAV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.9.4
Description An issue exists where login.php generates an OIDC state nonce stored in $ SESSION['oidc state'], but checksession.php dispatches the OIDC callback without comparing the incoming state against the session value. This allows an attacker to trick a victim into visiting a crafted URL, leading the application to exchange the attacker's authorization code and log the victim into the attacker's account.
Recommendations Update to version 4.9.4.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54599
GHSA-GR2W-M9V4-QM3V

Affected Products

Wallos