PT-2026-27481 · Wallos · Wallos

Tunelko

·

Published

2026-03-24

·

Updated

2026-03-24

·

CVE-2026-33417

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.7.2
Description Wallos is a personal subscription tracker that allows self-hosting and is open-source. Prior to version 4.7.2, password reset tokens did not expire. The password resets table contains a created at timestamp, but the token validation logic does not verify it. This allows an attacker who intercepts a password reset link to use it indefinitely, even days, weeks, or months after it was initially sent.
Recommendations Update to version 4.7.2 or later.

Exploit

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2026-33417
GHSA-P3FV-M43R-3FHF

Affected Products

Wallos