cve-2026-50198 and cve-2026-50199 in wallos both came from cross-user references being accepted first and trusted later
cve-2026-48067 came from a scope mismatch in filament AttachAction and AssociateAction
cve-2026-47755 let a low-privileged authenticated user pull another client credentials and totp secrets in itflow