HIGH8.8CVE-2026-33318Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers from 0, < 26.4.0
HIGH8.3CVE-2026-49229@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens from 0, < 26.6.0
MEDIUM4.3CVE-2026-46700@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets from 0, < 26.6.0
—Actual Sync Server has an Authenticated Path Traversal
from 0, < 26.3.0
—@actual-app/sync-server: Missing authorization in sync endpoints allows cross-user budget file access in multi-user mode
from 0, < 26.2.1
—ActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints
from 0, < 26.2.1