CVE-2026-82089: Wallabag Android-App

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.

Affected products

  • Wallabag Android-App: up to and including 2.6.0

Published 2026-08-28. Last modified 2026-09-09.