CVE-2026-19198
8.7Akaunting · Akaunting
Akaunting 3.1.21 contains an incorrect authorization vulnerability that allows authenticated users to perform unauthorized actions.
Executive summary
Akaunting version 3.1.21 is vulnerable to an incorrect authorization flaw that could allow an authenticated attacker to compromise system integrity and availability.
Vulnerability
The application suffers from an incorrect authorization vulnerability (CWE-863), which allows an authenticated attacker with low privileges to bypass intended access controls and perform unauthorized operations within the system.
Business impact
Successful exploitation allows an attacker to manipulate sensitive business data or disrupt core accounting processes, leading to significant operational risks. Given the high CVSS score of 8.7, this vulnerability poses a severe threat to the confidentiality, integrity, and availability of financial records managed within the platform.
Remediation
Immediate Action: Upgrade your Akaunting installation to version 3.2.1 or later to resolve this authorization defect.
Proactive Monitoring: Review application access logs for unusual administrative activity or unauthorized changes to financial records performed by low-privileged user accounts.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced for all user accounts and restrict access to the Akaunting web interface to authorized network segments only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this authorization bypass necessitates immediate attention. Administrators must prioritize updating to version 3.2.1 to prevent potential unauthorized access and data manipulation within their accounting environments.