CVE Explorer
CVE-2026-27584
Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows any unauthenticated user to query the SimpleFIN and Pluggy.ai integration endpoints and read sensitive bank account balance and transaction information. This vulnerability allows an unauthenticated attacker to read the bank account balance and transaction history of ActualBudget users. This vulnerability impacts all ActualBudget Server users with t
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"actual","vendor":"actualbudget","versions":[{"status":"affected","version":"< 26.2.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:61b5c22bdf123080176ffaac87a8e2e54e77fedf7aa6171944539af3213b55d1 · sha256:405a991d811db689… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.2,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:61b5c22bdf123080176ffaac87a8e2e54e77fedf7aa6171944539af3213b55d1 · sha256:405a991d811db689… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:61b5c22bdf123080176ffaac87a8e2e54e77fedf7aa6171944539af3213b55d1 · sha256:405a991d811db689… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/actualbudget/actual/commit/ea937d100956ca56689ff852d99c28589e2a7d88","tags":["x_refsource_MISC"],"url":"https://github.com/actualbudget/actual/commit/ea937d100956ca56689ff852d99c28589e2a7d88"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:61b5c22bdf123080176ffaac87a8e2e54e77fedf7aa6171944539af3213b55d1 · sha256:405a991d811db689… · /containers/cna/references/1
{"name":"https://github.com/actualbudget/actual/security/advisories/GHSA-m2cq-xjgm-f668","tags":["x_refsource_CONFIRM"],"url":"https://github.com/actualbudget/actual/security/advisories/GHSA-m2cq-xjgm-f668"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:61b5c22bdf123080176ffaac87a8e2e54e77fedf7aa6171944539af3213b55d1 · sha256:405a991d811db689… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.