Skip to main content
Loading…
    CVE-2026-27638 — Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user owns or has access — CVE Database · The Intelligence Room