Server-Side Request Forgery in Akaunting 3.1.21 Invoice PDF Rendering
CVE-2026-8193
Key Information:
Badges
What is CVE-2026-8193?
A vulnerability has been detected in the Invoice PDF Rendering component of Akaunting version 3.1.21. This issue arises from the manipulation of the config/dompdf.php file, potentially allowing an attacker to perform a server-side request forgery. The flaw could be exploited remotely, which raises significant security concerns. Despite early notification, the vendor has not issued a response regarding this vulnerability. The public availability of the exploit amplifies the urgency for users to apply updates and mitigate risks associated with SSRF attacks.
Affected Version(s)
Akaunting 3.1.21
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
