CVE-2026-61639
Wallos zip-slip on database restore, SSRF through the admin-set OIDC and SMTP endpoints, and OIDC identity linking by email
- Severity
- high
- Affected product
- Wallos
- Affected versions
- Wallos < 4.9.6
- Fixed in
- Wallos 4.9.6
- Added to NewScan
- 2026-09-01
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Wallos from its response and reports this CVE when the detected version falls inside the affected range below.
The 4.9.6 set of the 2026-09-01 Wallos batch, all four fixed by commit b75f13d. CVE-2026-61639 (8.5) is POST /endpoints/db/restore.php calling ZipArchive::extractTo() without validating entry names, so an uploaded archive writes outside the restore directory; CVE-2026-61640 (8.5) and CVE-2026-61638 (8.2) are SSRF through admin-configured OIDC token_url/user_info_url and through the smtpaddress/smtpport the mail test accepts - both OOB-shaped, so proving either needs the Pro collaborator and neither is claimed in-band here; CVE-2026-61641 (8.1) links an incoming OIDC identity to an existing local account on email alone, which is account takeover wherever the IdP does not own the address. VERSION-MATCH ONLY, for the same reason as the 4.9.4 row - the vectors are authenticated or attacker-controlled-IdP writes.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →