PT-2026-83994 · Wallos · Wallos

CVE-2026-61641

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wallos versions 4.0.0 through 4.9.5
Description The OIDC login process links an incoming OIDC identity to an existing local account by matching the email claim without verifying the email verified claim from the Identity Provider (IdP). If Wallos is configured with an IdP that allows users to provide unverified or arbitrary emails, such as multi-tenant IdPs or those with open self-registration, an attacker can authenticate using an administrator's email address to achieve full account takeover without a password.
Recommendations Update to version 4.9.6.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61641
GHSA-QWGP-M2F3-6J3R

Affected Products

Wallos