


Perceptive Security
SOC/SIEM Consultancy

Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migra…
Published:
23 April 2026 at 22:00:00
Alert date:
24 April 2026 at 15:07:56
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2026-33318 affects Actual, a local-first personal finance tool, allowing authenticated users with BASIC role to escalate to ADMIN privileges on servers migrated from password to OpenID Connect authentication. The vulnerability combines three weaknesses: missing authorization on POST /account/change-password endpoint, orphaned password auth rows persisting after migration, and client-controlled loginMethod bypassing server auth configuration. These form a sequential exploit chain allowing attackers to set known passwords and authenticate as anonymous admin accounts. Fixed in version 26.4.0.
Technical details
Mitigation steps:
Affected products:
Actual
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-33318
https://actualbudget.org/blog/release-26.4.0
https://github.com/actualbudget/actual/security/advisories/GHSA-prp4-2f49-fcgp
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
