← العودة للجدول
CVE-2026-61640
CVE-2026-61640 | ellite Wallos up to 4.9.5 OIDC Callback handle_oidc_callback.php curl_init server-side request forgery
📅 2026-09-01
🟡 Medium 🔥 No VulDB Vulnerability Web

📋 الوصف الكامل

A vulnerability classified as problematic has been found in ellite Wallos up to 4.9.5. The impacted element is the function curl_init of the file includes/oidc/handle_oidc_callback.php of the component OIDC Callback Handler. This manipulation causes server-side request forgery. The identification of this vulnerability is CVE-2026-61640. It is possible to initiate the attack remotely. There is no

💻 الأنظمة المتأثرة

PHP

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-61640

📡 المصدر

VulDB

✅ الحلول والتخفيف

Apply vendor security patch

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←