CVE-2026-49229
HIGHActual: Disabled OpenID users keep access through existing session tokens
Title source: cnaDescription
Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity, while existing Actual session tokens for the disabled user remain valid. The shared session validation path accepts any existing token row that has not expired without checking whether the associated user is still enabled, allowing a disabled user to continue calling authenticated server endpoints. This issue is fixed in version 26.6.0.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/actualbudget/actual/security/advisories/GHSA-cq9c-6w48-qmfg
X_Refsource_Misc x_refsource_misc
https://github.com/actualbudget/actual/commit/c8cb8a223a4faf1c2e1dcb0795a79a93f7b19e80
X_Refsource_Misc x_refsource_misc
https://github.com/actualbudget/actual/releases/tag/v26.6.0
Scores
CVSS v3
8.3
EPSS
0.0025
EPSS Percentile
16.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-613
Status
published
Products (1)
actualbudget/actual
< 26.6.0
Published
Jul 07, 2026
Tracked Since
Jul 08, 2026