Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential for the authenticated user. As a result, a normal authenticated user without their own provider key can trigger exchange-rate refreshes using another user's stored provider credential. This issue has been patched in version 4.9.1. | |
| Title | Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refresh | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-31T20:25:41.238Z
Reserved: 2026-06-03T22:05:13.645Z
Link: CVE-2026-50199
No data.
Status : Received
Published: 2026-08-31T21:17:08.847
Modified: 2026-08-31T21:17:08.847
Link: CVE-2026-50199
No data.
OpenCVE Enrichment
No data.