cbcvebase.

Actualbudget Actual vulnerabilities

7 known vulnerabilities affecting actualbudget/actual.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2026-33318P2HIGHCVSS 8.8fixed in 26.4.02026-04-24
CVE-2026-33318 [HIGH] CWE-284 CVE-2026-33318: Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (incl Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migrated from password authentication to OpenID Connect. Three weaknesses combine: `POST /account/change-password` has no authorization check, allowing any session to overwrite the password hash; th
nvd
CVE-2026-27584P3HIGHCVSS 7.5fixed in 26.2.12026-02-24
CVE-2026-27584 [HIGH] CWE-306 CVE-2026-27584: Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middl Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows any unauthenticated user to query the SimpleFIN and Pluggy.ai integration endpoints and read sensitive bank account balance and transaction information. This vulnerability allows an unauthenticated attac
nvd
CVE-2026-42604P3MEDIUMCVSS 6.9fixed in 26.5.02026-06-12
CVE-2026-42604 [MEDIUM] CWE-863 CVE-2026-42604: Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full OpenID Connect configuration—including the OAuth2 `client_secret`—to any caller who knows the bootstrap password. The endpoint also lacks authentication and rate limiting, making the bootstrap password
nvd
CVE-2026-3089P3MEDIUMCVSS 6.5fixed in 26.3.02026-03-09
CVE-2026-3089 [MEDIUM] CWE-22 CVE-2026-3089: Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. I Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to 26.3.0, improper validation of the user-controlled x-actual-file-id header means that traversal segments (../) can escape the intended directory and write files outside userFiles.This issue affects prior versions of Actual Sync Server
nvd
CVE-2026-27638P3HIGHCVSS 7.1fixed in 26.2.12026-02-26
CVE-2026-27638 [HIGH] CWE-862 CVE-2026-27638: Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user owns or has access to the file being operated on. Any authenticated user can read, modify, and overwrite any other user's budget files by providing their file ID. Version 26.2.
nvd
CVE-2026-43872P3MEDIUMCVSS 5.3fixed in 26.5.02026-06-12
CVE-2026-43872 [MEDIUM] CWE-22 CVE-2026-43872: Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints ar Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Version 26.5.0 fixes the issue.
nvd
CVE-2026-42890P4MEDIUMCVSS 4.8fixed in 26.5.02026-06-12
CVE-2026-42890 [MEDIUM] CWE-94 CVE-2026-42890: Actual is an open-source personal finance application. In the macOS desktop application version 25.x Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file on disk or control command-line arguments to invoke the signed Actual.app binary with the ELECTRON_RUN_AS_NODE=1 environment variable
ghsanvd
Actualbudget Actual vulnerabilities | cvebase