Local-first Personal Finance Tool Vulnerability in Actual Software
CVE-2026-27638

5.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
26 February 2026

What is CVE-2026-27638?

A security flaw exists in Actual software's multi-user mode prior to version 26.2.1. The sync API endpoints do not adequately validate whether an authenticated user has the necessary permissions to access or manipulate another user's budget files. This oversight allows any authenticated user to read, modify, and overwrite files belonging to other users, effectively infringing on data confidentiality and integrity. Version 26.2.1 addresses this vulnerability, ensuring proper access controls are in place.

Affected Version(s)

actual < 26.2.1

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.