CVE-2026-46700
published 2026-07-07CVE-2026-46700: Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.34%
25.4th percentile
Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /secret/ handler enforces an admin check in OpenID mode. Any authenticated non-admin BASIC user in OpenID multi-user deployments can probe the secrets store and learn which admin-managed bank-sync integrations have been configured, including simplefin_accessKey, pluggyai_clientSecret, pluggyai_itemIds, and the gocardless secrets. This issue is fixed in version 26.6.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actual-app | sync-server | >= 0 < 26.6.0 | 26.6.0 |
| actualbudget | actual | < 26.6.0 | 26.6.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
actualbudget actual up to 26.5.x Secret Store improper synchronization
vuldb·2026-07-07·CVSS 4.3
CVE-2026-46700 [MEDIUM] actualbudget actual up to 26.5.x Secret Store improper synchronization
A vulnerability, which was classified as problematic, has been found in actualbudget actual up to 26.5.x. This issue affects some unknown processing of the component Secret Store. This manipulation causes improper synchronization.
The identification of this vulnerability is CVE-2026-46700. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
ghsa·2026-06-22
CVE-2026-46700 [MEDIUM] CWE-285 @actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
## Summary
In `@actual-app/sync-server`, the `GET /secret/:name` endpoint (`app-secrets.js:53`) checks only that the caller has a valid session — it does not verify the caller is an admin. The sibling `POST /secret/` handler does enforce an admin check in OpenID mode, exposing an authorization asymmetry. Any authenticated non-admin (BASIC) user in OpenID multi-user deployments can probe the secrets store and learn which admin-managed bank-sync integrations have been configured (existence, not values). This includes integration credentials that are not otherwise observable to non-admins, such as `simplefin_accessKey`, `pluggyai_clientSecret`, `
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/actualbudget/actual/commit/3494f78c9459ed9c412e28b500b675ba5eb72d4ehttps://github.com/actualbudget/actual/pull/7862https://github.com/actualbudget/actual/releases/tag/v26.6.0https://github.com/actualbudget/actual/security/advisories/GHSA-3f62-qv96-4p78https://github.com/actualbudget/actual/security/advisories/GHSA-3f62-qv96-4p78
2026-07-07
Published