CVE-2026-61638: Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port

Published Aug 31, 2026
·
Updated

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. PHPMailer connects to attacker-supplied host:port. Every other notification endpoint uses ssrfhelper.php but email was missed. Any authenticated user can probe internal network, cloud metadata. This issue has been patched in version 4.9.6.

Affected Software

1 affected component
Wallos Wallos<4.9.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Wallos to a version that resolves this vulnerability.

    Fixed in 4.9.6

Event History

Aug 31, 2026
CVE Published
via MITRE·08:41 PM
Data Sourced
via MITRE·08:41 PM
DescriptionWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated Wallos user can submit attacker-controlled SMTP host and port values to the test email notification endpoint. The issue can be used to probe internal network services and cloud metadata endpoints reachable from the Wallos server.

2

Are default installations affected?

The vulnerable endpoint accepts the SMTP address and port from the POST body without SSRF validation, so exposure depends on an authenticated user being able to access the test email notification function. No additional configuration prerequisite is stated.

3

What version fixes the issue?

Upgrade Wallos to version 4.9.6 or later. The vulnerability affects versions prior to 4.9.6.

4

What can be done before upgrading?

Restrict access to Wallos to trusted authenticated users and limit the Wallos host's outbound network access, particularly to internal services and cloud metadata endpoints. This reduces the targets that can be reached through the vulnerable SMTP connection.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203