top of page
perceptive_background_267k.jpg

Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity, wh…

Published:

6 juli 2026 om 22:00:00

Alert date:

7 juli 2026 om 23:02:35

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Web Technologies

CVE-2026-49229 affects Actual, a local-first personal finance application, in versions prior to 26.6.0. In OpenID multi-user mode, disabling a user account only prevents future OpenID logins but does not invalidate existing session tokens. The session validation logic checks only whether a token row exists and has not expired, without verifying whether the associated user account is still enabled. This flaw allows a disabled user to continue accessing authenticated server endpoints using their still-valid session tokens. The vulnerability represents a broken access control issue in the identity and session management subsystem. It is fixed in version 26.6.0, which introduces a user-enabled status check during session validation. The fix is documented in a GitHub commit and an official security advisory.

Technical details

Mitigation steps:

Affected products:

Actual (personal finance app) prior to 26.6.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page