CVE-2026-61638
8.2ellite · Wallos
A Server-Side Request Forgery vulnerability in the testemailnotifications.php endpoint of Wallos allows authenticated users to probe internal network resources and cloud metadata services.
Executive summary
Wallos versions prior to 4.9.6 contain a Server-Side Request Forgery vulnerability that allows authenticated attackers to perform unauthorized internal network reconnaissance.
Vulnerability
This Server-Side Request Forgery (CWE-918) flaw exists within the testemailnotifications.php script, which fails to properly validate the smtpaddress and smtpport parameters provided in POST requests. An authenticated user can leverage this oversight to force the application to connect to arbitrary internal hosts and cloud metadata endpoints.
Business impact
The ability to perform Server-Side Request Forgery poses a significant risk to internal infrastructure by bypassing network segmentation and security perimeters. An attacker could potentially access sensitive cloud metadata, internal services, or private APIs not exposed to the public internet, leading to unauthorized information disclosure. With a CVSS score of 8.2, this vulnerability is classified as High, reflecting the potential for severe impact on confidentiality despite the requirement for authenticated access.
Remediation
Immediate Action: Update the Wallos installation to version 4.9.6 or later, which implements the necessary validation logic to prevent unauthorized requests.
Proactive Monitoring: Review application access logs for unusual POST requests directed at the testemailnotifications.php endpoint, specifically looking for internal IP addresses or cloud metadata service endpoints in the request body.
Compensating Controls: Deploy a Web Application Firewall (WAF) to inspect and block POST requests containing suspicious hostnames or internal IP addresses in the smtpaddress field.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the ease with which this vulnerability can be leveraged to map internal network topology, administrators should prioritize patching to version 4.9.6. Even in restricted environments, the risk of credential compromise leading to lateral movement via this SSRF vector remains high. Immediate application of the vendor-provided update is the only effective way to fully neutralize this security risk.