Privilege Escalation Vulnerability in Akaunting by Akaunting Inc.
CVE-2026-16772
Currently unrated
What is CVE-2026-16772?
In specific versions of Akaunting, a vulnerability exists where low-privileged authenticated users can exploit an oversight in the UpdateUser job to grant themselves administrator privileges. This flaw arises from the lack of authorization checks when processing user-supplied role assignments through an unconditional call to roles()->sync(). Consequently, users merely need the update-auth-profile permission to access this pathway and modify their roles, enabling a significant security risk. Although the API endpoints maintain appropriate permission gating, the self-update feature remains compromised, allowing unauthorized privilege escalation.
Affected Version(s)
Akaunting 0 <= 3.1.21
