CVE-2026-39901Disclosure

LOWCVSS 5.7 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity flaw allows an authenticated tenant user to soft-delete synced non-manual transactions through the transaction update endpoint, despite the application explicitly blocking deletion of those transactions via the normal DELETE path. This bypass undermines the intended protection for imported transaction records and allows protected transactions to be hidden from normal views. This vulnerability is fixed in 1.12.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-08: 2Technical Details · 2026-04-08: 104-08
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-39901 monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity flaw allows an authenticated tenant user to sof… https://www.cve.org/CVERecord?id=CVE-2026-39901 ----- Traducción: CVE-2026-39901 mon… http://infoflow.cloud`

    Post summary

    A brief tweet posts the CVE identifier and a link to the official record, mentioning a transaction‑integrity flaw in the budgeting application but providing no further technical, exploit, or patch details.

    0000025
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39901 monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity flaw allows an authenticated tenant user to sof… https://www.cve.org/CVERecord?id=CVE-2026-39901

    Post summary

    The post announces CVE-2026-39901 as a transaction integrity flaw in Monetr before version 1.12.3, affecting authenticated users, but provides no evidence of exploitation, PoC, or remediation.

    00000145
    57.0K followersView on X

Explore more