Impact
Wallos 4.0.0 through 4.9.5 would link an incoming OpenID Connect identity to a local user account by comparing only the provided e‑mail address, ignoring whether the identity provider has verified that e‑mail. An attacker who can create or control an identity provider that presents an arbitrary or unverified e‑mail can authenticate using the e‑mail address of an existing Wallos account—typically the administrator—and be logged in as that account without knowing any password. This is an authentication bypass that grants full access to the victim account.
Affected Systems
Ellite’s Wallos component, versions 4.0.0 up to (but not including) 4.9.6. Any installation configured to allow cross‑tenant or self‑registered OIDC identities without an email verification check is vulnerable.
Risk and Exploitability
The CVSS score of 8.1 points to high severity, and the EPSS score is not available, so a precise exploitation probability cannot be quantified. The vulnerability is listed as not in the CISA KEV catalog, but the exploit path requires only an OIDC provider that accepts arbitrary e‑mails, a scenario common in multi‑tenant or self‑signup configurations. Consequently the risk of compromise is high if an attacker can register a domain or use a compromised tenant.
OpenCVE Enrichment