PT-2026-83994 · Wallos · Wallos
CVE-2026-61641
·
Published
2026-08-31
·
Updated
2026-08-31
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wallos versions 4.0.0 through 4.9.5
Description
The OIDC login process links an incoming OIDC identity to an existing local account by matching the email claim without verifying the
email verified claim from the Identity Provider (IdP). If Wallos is configured with an IdP that allows users to provide unverified or arbitrary emails, such as multi-tenant IdPs or those with open self-registration, an attacker can authenticate using an administrator's email address to achieve full account takeover without a password.Recommendations
Update to version 4.9.6.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wallos