Local-first Personal Finance Tool Vulnerability in Actual Software
CVE-2026-27638
5.7MEDIUM
What is CVE-2026-27638?
A security flaw exists in Actual software's multi-user mode prior to version 26.2.1. The sync API endpoints do not adequately validate whether an authenticated user has the necessary permissions to access or manipulate another user's budget files. This oversight allows any authenticated user to read, modify, and overwrite files belonging to other users, effectively infringing on data confidentiality and integrity. Version 26.2.1 addresses this vulnerability, ensuring proper access controls are in place.
Affected Version(s)
actual < 26.2.1
