PT-2026-23827 · Wallos · Wallos

Hussien-Alzaghateet

·

Published

2026-03-07

·

Updated

2026-03-07

·

CVE-2026-30842

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.6.2
Description Wallos is a self-hostable personal subscription tracker. An authenticated user can delete avatar files uploaded by other users because the avatar deletion endpoint does not verify ownership. Any authenticated user who knows or can discover another user's uploaded avatar filename can delete that file. The vulnerable endpoint is the avatar deletion endpoint. The vulnerable variable is the avatar filename.
Recommendations Update to version 4.6.2 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-30842
GHSA-QW24-3PXR-3J6R

Affected Products

Wallos