CVE-2026-41689: Wallos: Shared local webhook allowlist lets low-privilege users send arbitrary requests to allowlisted internal services
Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notification feature reuses an administrator-configured local-target allowlist for every logged-in user. Any normal user can fully control a webhook URL, headers, and body, then use Wallos to send server-side requests to allowlisted internal automation services. When such a target exposes deployment or execution APIs, this can further enable adjacent-service RCE, but that downstream result is conditional on the target service. At time of publication, there are no publicly available patches.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41689?
CVE-2026-41689 is considered a high severity vulnerability due to its potential for unauthorized access to sensitive internal services.
How do I fix CVE-2026-41689?
To fix CVE-2026-41689, upgrade to version 4.8.5 or later of the Wallos software where the vulnerability has been addressed.
What versions are affected by CVE-2026-41689?
CVE-2026-41689 affects Wallos versions up to and including 4.8.4.
What type of vulnerability is CVE-2026-41689?
CVE-2026-41689 is a webhook vulnerability that allows low-privilege users to send arbitrary requests to allowlisted services.
Who is impacted by CVE-2026-41689?
Users of Wallos versions 4.8.4 and prior are impacted by CVE-2026-41689 if they utilize the webhook notification feature.