CVE-2026-27584Disclosure(actualbudget / actual)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch actualbudget actual systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows any unauthenticated user to query the SimpleFIN and Pluggy.ai integration endpoints and read sensitive bank account balance and transaction information. This vulnerability allows an unauthenticated attacker to read the bank account balance and transaction history of ActualBudget users. This vulnerability impacts all ActualBudget Server users with the SimpleFIN or Pluggy.ai integrations configured. The ActualBudget Server instance must be reachable over the network. Version 26.2.1 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • actual

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-25); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Products
actual

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-25: 4Mentions · 2026-03-01: 1Patch / Workaround · 2026-02-25: 2Technical Details · 2026-02-25: 3Technical Details · 2026-03-01: 102-2503-01
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-254
Disclosure2Patch2
2026-03-011
Disclosure1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27584 (CVSS:9.2, HIGH) is Analyzed. Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualB..https://nvd.nist.gov/vuln/detail/CVE-2026-27584 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2026‑27584, a high‑severity vulnerability in a local‑first personal finance tool due to missing authentication middleware, but provides no evidence of exploitation, PoC, or patch.

    0000028
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27584 Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows any unauthentica… https://www.cve.org/CVERecord?id=CVE-2026-27584

    Post summary

    The CVE highlights a missing authentication middleware in ActualBudget’s server component, potentially allowing unauthenticated access, but no PoC, exploit, or patch details are provided.

    00000159
    56.6K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Missing authentication in `ActualBudget Sync Server` (`CVE-2026-27584`) allows unauthorized access to financial sync endpoints. Update to 26.2.1. #AppSec #Vulnerability https://www.pulsepatch.io/posts/cve-2026-27584-actualbudget-sync-server-missing-authentication

    Post summary

    The CVE involves missing authentication in ActualBudget Sync Server, enabling unauthorized access to financial sync endpoints; users should update to version 26.2.1 to mitigate the vulnerability.

    0000032
    1 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 Critical vulnerability in ActualBudget Server (CVE-2026-27584) may expose sensitive financial data through unauthorized access. Patch immediately to protect users. 🔍 See details in Vulert’s Vulnerability Database: https://vulert.com/vuln-db/CVE-2026-27584 #CyberSecurity #AppSec #Vulert https://t.co/VJYbSn0Dk9

    Post summary

    The tweet announces a critical CVE (CVE‑2026‑27584) in ActualBudget Server, urges immediate patching, and links to a vulnerability database for further details.

    000004
    123 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27584: Zero-Dollar Auth: Leaking Bank Data with ActualBudget (CVE-2026-27584) ActualBudget, a local-first personal finance application designed for privacy enthusiasts, suffered from a critical authentication bypass in its server synchronizat... https://cvereports.com/reports/CVE-2026-27584

    Post summary

    The report discloses a critical authentication bypass in ActualBudget’s server sync that could leak bank data, but no PoC, exploit, or patch details are provided.

    0000036
    32 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appactualbudgetactual-node.js-

Explore more