PT-2026-83991 · Wallos · Wallos

CVE-2026-61638

·

Published

2026-08-31

·

Updated

2026-09-01

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.9.6
Description An authenticated user can perform Server-Side Request Forgery (SSRF), a flaw where the server is tricked into making requests to an unintended location, allowing the probing of internal networks and cloud metadata. The issue occurs because the endpoint '/endpoints/notifications/testemailnotifications.php' accepts the smtpaddress and smtpport variables from the POST body without validation, causing PHPMailer to connect to an attacker-supplied host and port.
Recommendations Update to version 4.9.6.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61638
GHSA-F8R5-V75M-385H

Affected Products

Wallos