


Perceptive Security
SOC/SIEM Consultancy

Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity, wh…
Published:
6 juli 2026 om 22:00:00
Alert date:
7 juli 2026 om 23:02:35
Source:
nvd.nist.gov
Identity & Access, Web Technologies
CVE-2026-49229 affects Actual, a local-first personal finance application, in versions prior to 26.6.0. In OpenID multi-user mode, disabling a user account only prevents future OpenID logins but does not invalidate existing session tokens. The session validation logic checks only whether a token row exists and has not expired, without verifying whether the associated user account is still enabled. This flaw allows a disabled user to continue accessing authenticated server endpoints using their still-valid session tokens. The vulnerability represents a broken access control issue in the identity and session management subsystem. It is fixed in version 26.6.0, which introduces a user-enabled status check during session validation. The fix is documented in a GitHub commit and an official security advisory.
Technical details
Mitigation steps:
Affected products:
Actual (personal finance app) prior to 26.6.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-49229
https://github.com/actualbudget/actual/commit/c8cb8a223a4faf1c2e1dcb0795a79a93f7b19e80
https://github.com/actualbudget/actual/releases/tag/v26.6.0
https://github.com/actualbudget/actual/security/advisories/GHSA-cq9c-6w48-qmfg
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
