VendorsActual Budgetactualany version
Vulnerabilities

Actual Budget Actual any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2026-27584
ActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints
Published 2026-02-24 · Analyzed
9.2EPSS 0.006
CVE-2026-33318
Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
Published 2026-04-24 · Analyzed
8.8EPSS 0.006
CVE-2026-27638
ActualBudget missing authorization in sync endpoints allows cross-user budget file access in multi-user mode
Published 2026-02-26 · Analyzed
7.1EPSS 0.004
CVE-2026-3089
Actual Sync Server 26.2.1 - Authenticated Path Traversal
Published 2026-03-09 · Analyzed
6.5EPSS 0.004