CVE-2026-30840Disclosure(wallosapp / wallos)

LOWCVSS 8.8 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch wallosapp wallos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability in notification testers. This issue has been patched in version 4.6.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wallos

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
wallos

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-03-07: 5Patch / Workaround · 2026-03-07: 1Technical Details · 2026-03-07: 503-07
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-30840 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability in notification te… https://www.cve.org/CVERecord?id=CVE-2026-30840

    Post summary

    CVE-2026-30840 is disclosed as a server‑side request forgery flaw in Wallos before version 4.6.2, but the text provides no PoC, exploit, or mitigation information.

    00000139
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30840 - Wallos: Server-Side Request Forgery (SSRF) in Notification Testers Intel Report: https://ift.tt/8csmXSz

    Post summary

    The alert announces CVE-2026-30840, a Server‑Side Request Forgery flaw in Wallos Notification Testers, but provides no PoC, exploit details, or patch information.

    0000045
    344 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-30840 - High Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability in notification testers. This issue has bee... https://www.thehackerwire.com/vulnerability/CVE-2026-30840/ https://t.co/QYSAxMabFV

    Post summary

    The post discloses a high‑severity server‑side request forgery flaw in Wallos versions before 4.6.2, providing a reference link for further details.

    0000040
    128 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30840 Server-Side Request Forgery in Wallos Subscription Tracker Before 4.6.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30840

    Post summary

    A new Server‑Side Request Forgery vulnerability, CVE‑2026‑30840, has been identified in Wallos Subscription Tracker versions prior to 4.6.2.

    0000033
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30840: HIGH] Attention Wallos users! A server-side request forgery vulnerability has been patched in version 4.6.2. Update now to enhance your cyber security. #cybersecurity#cve,CVE-2026-30840,#cybersecurity https://cvefind.com/CVE-2026-30840

    Post summary

    The post informs Wallos users that CVE‑2026‑30840, a high‑severity server‑side request forgery, has been fixed in version 4.6.2 and urges an update.

    0000064
    599 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwallosappwallos---

Explore more