« Volver al listado

Actualbudget

Actualbudget Actual: vulnerabilidades y CVE

Actualbudget Actual tiene 9 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses9
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-50179Media (4.2)0.29%—7 jul 2026
Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and…
CVE-2026-49229Alta (8.3)0.44%—7 jul 2026
Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity, while existing Actual session tokens for the disabled user…
CVE-2026-50007Alta (7.2)0.43%—7 jul 2026
Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared user with user_access on a budget file to perform owner-only file management actions. A non-owner…
CVE-2026-43872Media (5.3)0.45%—12 jun 2026
Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Version 26.5.0 fixes the issue.
CVE-2026-42890Media (4.8)0.18%—12 jun 2026
Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file…
CVE-2026-33318Alta (8.8)0.59%—24 abr 2026
Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migrated from password authentication to OpenID Connect. Three…
CVE-2026-3089Media (5.3)0.45%—9 mar 2026
Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to 26.3.0, improper validation of the user-controlled x-actual-file-id header means that traversal…
CVE-2026-27638Media (5.7)0.36%—26 feb 2026
Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user owns or has access to the file being…
CVE-2026-27584Crítica (9.2)0.56%—24 feb 2026
Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows any unauthenticated user to query the SimpleFIN and Pluggy.ai…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services3
  2. T1078 Valid Accounts2
  3. T1078.001 Default Accounts1
  4. T1190 Exploit Public-Facing Application1
  5. T1552.007 Container API1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.