PT-2026-38444 · Wallos · Wallos
Morimori-Dev
·
Published
2026-05-07
·
Updated
2026-05-07
·
CVE-2026-41687
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Wallos versions prior to 4.8.1
Description
Authenticated users can perform Blind Server-Side Request Forgery (SSRF) to internal services in Tailscale, Carrier-Grade NAT (CGNAT), and other environments using 100.64.0.0/10 addresses. This occurs because the logo and icon URL fetching mechanisms use an inline IP validation check that fails to block CGNAT addresses, despite a helper function
is cgnat ip() being available in the system. The issue affects the 'endpoints/subscription/add.php' and 'endpoints/payments/add.php' endpoints.Recommendations
Update to version 4.8.1.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wallos