actualbudget actual是actualbudget团队开源的一个个人财务管理应用。 Actual 26.6.0之前版本存在授权问题漏洞,该漏洞源于GET /secret/:name 端点未验证调用者是否为管理员,而POST /secret/处理程序在OpenID模式下实施了管理员检查,导致已通过身份验证的非管理员BASIC用户在OpenID多用户部署中可探测秘密存储并获取由管理员配置的银行同步集成信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| actualbudget | actual | < 26.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| actualbudget | actual | < 26.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49229 | 8.3 HIGH | Actual: Disabled OpenID users keep access through existing session tokens |
| CVE-2026-46672 | 4.6 MEDIUM | Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `escap |
| CVE-2026-50179 | 4.2 MEDIUM | Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields |
| CVE-2026-50007 | Actual: Shared users can perform owner-only file management actions |
No comments yet