Security Advisory

CVE-2026-46700

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-07 20:56:39
Last updated 2026-07-08 14:43:18
Assigner GitHub_M
CVSS score 4.3
State PUBLISHED

Description

Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /secret/ handler enforces an admin check in OpenID mode. Any authenticated non-admin BASIC user in OpenID multi-user deployments can probe the secrets store and learn which admin-managed bank-sync integrations have been configured, including simplefin_accessKey, pluggyai_clientSecret, pluggyai_itemIds, and the gocardless secrets. This issue is fixed in version 26.6.0.