CVE-2026-19198

8.7

Akaunting · Akaunting

Akaunting 3.1.21 contains an incorrect authorization vulnerability that allows authenticated users to perform unauthorized actions.

Executive summary

Akaunting version 3.1.21 is vulnerable to an incorrect authorization flaw that could allow an authenticated attacker to compromise system integrity and availability.

Vulnerability

The application suffers from an incorrect authorization vulnerability (CWE-863), which allows an authenticated attacker with low privileges to bypass intended access controls and perform unauthorized operations within the system.

Business impact

Successful exploitation allows an attacker to manipulate sensitive business data or disrupt core accounting processes, leading to significant operational risks. Given the high CVSS score of 8.7, this vulnerability poses a severe threat to the confidentiality, integrity, and availability of financial records managed within the platform.

Remediation

Immediate Action: Upgrade your Akaunting installation to version 3.2.1 or later to resolve this authorization defect.

Proactive Monitoring: Review application access logs for unusual administrative activity or unauthorized changes to financial records performed by low-privileged user accounts.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced for all user accounts and restrict access to the Akaunting web interface to authorized network segments only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this authorization bypass necessitates immediate attention. Administrators must prioritize updating to version 3.2.1 to prevent potential unauthorized access and data manipulation within their accounting environments.

More Akaunting CVEs