PT-2026-83990 · Wallos · Wallos

CVE-2026-54600

·

Published

2026-08-31

·

Updated

2026-09-02

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.9.4
Description An authentication bypass exists in the 'endpoints/db/import.php' endpoint. On fresh or unconfigured installations where the user table row count is zero, an unauthenticated attacker can replace the entire database.
Recommendations Update to version 4.9.4.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54600
GHSA-8WQC-R9J3-RV7M

Affected Products

Wallos