PT-2026-38444 · Wallos · Wallos

Morimori-Dev

·

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2026-41687

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.8.1
Description Authenticated users can perform Blind Server-Side Request Forgery (SSRF) to internal services in Tailscale, Carrier-Grade NAT (CGNAT), and other environments using 100.64.0.0/10 addresses. This occurs because the logo and icon URL fetching mechanisms use an inline IP validation check that fails to block CGNAT addresses, despite a helper function is cgnat ip() being available in the system. The issue affects the 'endpoints/subscription/add.php' and 'endpoints/payments/add.php' endpoints.
Recommendations Update to version 4.8.1.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41687

Affected Products

Wallos