Loading…
CVE-2026-46700 — @actual-app/sync-server's missing authorization on GET /secret/:name allows non- · VulnScope