What is CVE-2026-19198?
CVE-2026-19198 is an authenticated improper authorization vulnerability in Akaunting 3.1.21, affecting the common BulkActions dispatcher. This could allow unauthorized operations by authenticated users. Users should update Akaunting immediately and review access controls.
Azərbaycanca: CVE-2026-19198 Akaunting 3.1.21-də autentifikasiya olunmuş istifadəçinin ümumi BulkActions bölüşdürücüsündə düzgün olmayan autorizasiya zəifliyidir. Bu, icazəsiz əməliyyatların icrasına imkan verə bilər. Akaunting istifadəçiləri dərhal proqramı yeniləməli və giriş nəzarətini nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Akaunting
FAQ2
Which version of Akaunting is affected by CVE-2026-19198?
CVE-2026-19198 is an authenticated improper authorization vulnerability affecting Akaunting version 3.1.21.
Which Akaunting component contains the CVE-2026-19198 vulnerability?
The vulnerability is located in the common BulkActions dispatcher component of Akaunting.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.