CVE-2026-16772
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Summary
In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the UpdateUser job, which processes user-supplied role assignments via an unconditional roles()->sync() call without verifying whether the caller is authorized to manage roles. Users only require the default update-auth-profile permission to access the self-update path and assign themselves as admins. The API endpoints are properly permission‑gated and are not affected by this issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Akaunting | Akaunting | 0 <= 3.1.21 | affected |
Weaknesses
- CWE-862 Missing Authorization
- CWE-269 Improper Privilege Management
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: total
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.