Actualbudget develops a personal finance and budgeting application marked by a pattern of access-control and authentication weaknesses, including missing authorization checks, improper access controls, path traversal, and missing authentication for critical functions. These vulnerabilities reflect common risks in web and application-based financial software where inadequate boundary enforcement can expose sensitive user data and functionality. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Actualbudget over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33318HIGH Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migrated from password au | Apr 24, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-27584HIGH Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows any unauthenticated user to qu | Feb 24, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-27638HIGH Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user own | Feb 26, 2026 | 7.1 | 24 | NO | NO |
CVE-2026-3089MEDIUM Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to 26.3.0, improper validation of the user-controlled x-actual- | Mar 9, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Actualbudget.
Media articles that mention a CVE ID that affects a product developed by Actualbudget — matched by CVE ID, not by vendor name.