← Terug naar overzicht

Wallos, an open-source self-hostable personal subscription tracker, contains a critical authentication bypass vulnerability prior to version 4.9.4. The endpoint endpoints/db/migrate.php can be accessed over HTTP without any authentication, allowing any unauthenticated attacker to trigger database schema migrations against the live SQLite database. This could lead to database corruption, data loss, or unauthorized schema changes. The vulnerability requires no credentials or special privileges to exploit, making it easily accessible to remote attackers. The issue has been remediated in version 4.9.4, which was released along with a security advisory. Users are strongly advised to upgrade to the patched version immediately to prevent potential exploitation.

Affected products

  • Wallos

Related CVE's

  • CVE-2026-54598

Categories

  • Database & Storage
  • Identity & Access
  • Web Technologies