CVE-2026-61641
Received Received - Intake

OIDC Account Takeover in Wallos via Unverified Email

Vulnerability report for CVE-2026-61641, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: GitHub, Inc.

Description

Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, without verifying that the IdP marked that email as verified (email_verified). When Wallos is configured against an IdP that lets a user present an arbitrary or unverified email (multi-tenant IdPs, IdPs with open self-registration, or any IdP the attacker partly controls), an attacker with no Wallos account can authenticate with the admin's email and be logged in as the admin β€” full account takeover, no password needed. This issue has been patched in version 4.9.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wallos wallos From 4.0.0 (inc) to 4.9.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Wallos is a self-hosted subscription tracker. Versions 4.0.0 to 4.9.5 have a flaw where OpenID Connect (OIDC) login matches users solely by email without checking if the identity provider (IdP) verified that email. Attackers can exploit this by authenticating with an admin's email on multi-tenant or open IdPs to gain full admin access without a password.

Impact Analysis

If you use Wallos versions 4.0.0 to 4.9.5 with an IdP that allows unverified emails, an attacker could take over your admin account. This grants full access to manage subscriptions, view sensitive data, and perform administrative actions without needing your password.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Full account takeover risks non-compliance with access control and audit logging mandates in these regulations.

Mitigation Strategies

Upgrade Wallos to version 4.9.6 or later to patch the vulnerability. Ensure your IdP is configured to verify email addresses before allowing authentication.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61641. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart