GHSA-98f2-hwvc-w247HighCVSS 8.1

In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account...

Published
August 14, 2026
Last Modified
August 14, 2026

🔗 CVE IDs covered (1)

📋 Description

In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the UpdateUser job, which processes user-supplied role assignments via an unconditional roles()->sync() call without verifying whether the caller is authorized to manage roles. Users only require the default update-auth-profile permission to access the self-update path and assign themselves as admins. The API endpoints are properly permission‑gated and are not affected by this issue.

🔗 References (3)