Skip to content

Akaunting vulnerabilities

3 CVEs tracked

Akaunting, an open-source accounting platform, appears in our reports with multiple critical authorization and access control flaws. Key incidents include low-privileged user privilege escalation to admin via role ID manipulation (CVE-2026-16772), unauthorized operations through the BulkActions dispatcher (CVE-2026-19198), and unverified media file downloads accessible by any authenticated user without portal ownership checks (CVE-2026-71251). Defenders should immediately patch versions <= 3.1.21, strengthen role assignment validation in the `UpdateUser` job and permission checks in `BulkActions`, and enforce ownership verification on the `uploads/{id}/download` route.

Azərbaycanca: Akaunting açıq mənbə mühasibat proqramı hesabatlarımızda çoxsaylı kritik identifikasiya və avtorizasiya boşluqları ilə önə çıxır. Əsas hadisələr aşağı imtiyazlı istifadəçilərin admin roluna yüksəlməsi (CVE-2026-16772), BulkActions dispetçeri vasitəsilə icazəsiz əməliyyatlar (CVE-2026-19198) və autentifikasiya olunmuş istənilən istifadəçinin portal fərqi qoyulmadan media fayllarını endirə bilməsidir (CVE-2026-71251). Müdafiəçilər 3.1.21 və aşağı versiyalar üçün dərhal yamaq tətbiq etməli, `UpdateUser` iş prosesində rol təyinatı yoxlamalarını və `BulkActions` icazə mexanizmlərini gücləndirməli, həmçinin `uploads/{id}/download` route üzərində mülkiyyət doğrulaması əlavə etməlidirlər.

This vendor's CVEs3

This hub is built from skopnix's own reporting on Akaunting: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.