CVE-2026-43872
- EPSS 0.3%
- Veröffentlicht 12.06.2026 19:05:42
- Zuletzt bearbeitet 16.06.2026 15:35:16
Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Version 26.5.0 fixes the issue.
CVE-2026-42890
- EPSS 0.13%
- Veröffentlicht 12.06.2026 18:58:42
- Zuletzt bearbeitet 16.06.2026 15:35:16
Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file on disk or control command-line ...
CVE-2026-42604
- EPSS 0.4%
- Veröffentlicht 12.06.2026 18:42:38
- Zuletzt bearbeitet 16.06.2026 15:35:16
Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full OpenID Connect configuration—including the OAuth2 `client_secret`—to any caller who knows the bootstr...
CVE-2026-33318
- EPSS 0.47%
- Veröffentlicht 24.04.2026 02:13:47
- Zuletzt bearbeitet 27.04.2026 15:01:34
Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migrated from password authentication to OpenID Connect. Three weaknesses combine: `POST /accou...
CVE-2026-3089
- EPSS 0.38%
- Veröffentlicht 09.03.2026 14:08:55
- Zuletzt bearbeitet 09.04.2026 21:01:46
Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to 26.3.0, improper validation of the user-controlled x-actual-file-id header means that traversal segments (../) can escape the inte...
CVE-2026-27638
- EPSS 0.3%
- Veröffentlicht 26.02.2026 22:14:21
- Zuletzt bearbeitet 27.02.2026 17:03:28
Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user owns or has access to the file being operated on. Any authenticated user ...
CVE-2026-27584
- EPSS 0.4%
- Veröffentlicht 24.02.2026 14:59:21
- Zuletzt bearbeitet 26.02.2026 19:46:14
Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows any unauthenticated user to query the SimpleFIN and Pluggy.ai integration endpoints and read sensiti...