Privilege Escalation Vulnerability in Akaunting by Akaunting Inc.
CVE-2026-16772

Currently unrated

Key Information:

Vendor

Akaunting

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-16772?

In specific versions of Akaunting, a vulnerability exists where low-privileged authenticated users can exploit an oversight in the UpdateUser job to grant themselves administrator privileges. This flaw arises from the lack of authorization checks when processing user-supplied role assignments through an unconditional call to roles()->sync(). Consequently, users merely need the update-auth-profile permission to access this pathway and modify their roles, enabling a significant security risk. Although the API endpoints maintain appropriate permission gating, the self-update feature remains compromised, allowing unauthorized privilege escalation.

Affected Version(s)

Akaunting 0 <= 3.1.21

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.