A vulnerability classified as problematic has been found in ellite Wallos up to 4.9.5. The impacted element is the function curl_init of the file includes/oidc/handle_oidc_callback.php of the component OIDC Callback Handler. This manipulation causes server-side request forgery. The identification of this vulnerability is CVE-2026-61640. It is possible to initiate the attack remotely. There is no
PHP
Vulnerability
CVE-2026-61640
VulDB
Apply vendor security patch