HIGH 7.5 NVD
CVE-2026-54598
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any unauthenticated attacker can trigger pending migration files against the live SQLite database. This issue has been patched in version 4.9.4.
References
- https://github.com/ellite/Wallos/releases/tag/v4.9.4
- https://github.com/ellite/Wallos/security/advisories/GHSA-fgfx-rc43-4rr7
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-08-31 via NVD.
vulnfeed aggregates 11540 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.