PT-2026-83992 · Wallos · Wallos

CVE-2026-61639

·

Published

2026-08-31

·

Updated

2026-09-01

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.9.6
Description An issue exists where the application fails to validate entry names for directory traversal sequences when processing zip files. An administrator can upload a specially crafted zip archive to the 'POST /endpoints/db/restore.php' endpoint, which uses the ZipArchive::extractTo() function. By including entries with ../ sequences, such as logos/../../endpoints/shell.php, an attacker can write a webshell directly into the webroot. The existing extension filter is ineffective because it only applies to the logo copy step after the extraction has already occurred.
Recommendations Update to version 4.9.6.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61639
GHSA-3VG2-CXPG-M43G

Affected Products

Wallos