CVE-2026-27638: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-27638 is a missing authorization vulnerability in Actual Budget's sync server (@actual-app/sync-server) that allows any authenticated user in multi-user (OpenID) mode to read, modify, and overwrite other users' budget files by supplying an arbitrary file ID. It affects all versions of @actual-app/sync-server up to and including 26.2.0 (npm package). The vulnerability was published on February 26, 2026, and patched in version 26.2.1. It carries a CVSS v3.1 base score of 7.1 (High) and a CVSS v4.0 base score of 5.7 (Medium) (Github Advisory, GitHub Security Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization) in packages/sync-server/src/app-sync.ts. The validateSessionMiddleware (line 31) confirms that a user is authenticated, and individual sync endpoints call verifyFileExists to confirm the file exists — but neither check verifies that the requesting user owns or has been granted access to the file. The only endpoint that correctly enforced ownership was POST /sync/delete-user-file, which compared file.owner === userId and checked isAdmin(userId). This ownership check was absent from eight other endpoints: GET /sync/download-user-file, POST /sync/upload-user-file, POST /sync/sync, POST /sync/user-get-key, POST /sync/user-create-key, POST /sync/reset-user-file, POST /sync/update-user-filename, and GET /sync/get-user-file-info. An attacker needs only a valid session token and a target file ID (discoverable via admin listing, shared access records, or enumeration) to exploit any of these endpoints (Github Advisory, GitHub Security Advisory).

Impact

In multi-user OpenID deployments, a malicious authenticated user can exfiltrate complete financial data from any other user's budget — including transactions, account balances, payees, and encryption key material — by downloading their budget file. Beyond data theft, the attacker can overwrite or corrupt budget files, reset sync state (a destructive operation), rename files, and tamper with encryption keys, resulting in permanent data loss or integrity compromise for victims. Because Actual is a personal finance application, the exposed data is highly sensitive and the integrity impact is severe (Github Advisory).

Exploitability

A proof-of-concept is publicly documented in the GitHub Security Advisory, demonstrating exploitation via simple curl commands requiring only a valid session token and a target file ID. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.036–0.039% (12th percentile), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Github Advisory, GitHub Security Advisory).

Exploitation steps

  1. Obtain valid credentials: Register or log in as any authenticated user on a target Actual Budget server running in multi-user OpenID mode (version ≤ 26.2.0) to obtain a valid session token.
  2. Discover target file IDs: If the attacker has admin privileges, enumerate all files via GET /sync/list-user-files. Alternatively, file IDs may be discoverable through user_access sharing records or by guessing/brute-forcing UUID-format IDs.
  3. Download victim's budget file: Send a crafted GET request to /sync/download-user-file with the victim's file ID in the X-Actual-File-Id header and the attacker's session token in X-Actual-Token:
curl -X GET 'https://actual.example.com/sync/download-user-file' \
  -H 'X-Actual-Token: <attacker_token>' \
  -H 'X-Actual-File-Id: <victim_file_id>' \
  -o stolen-budget.blob
  1. Read file metadata: Query GET /sync/get-user-file-info with the victim's file ID to retrieve metadata about the budget.
  2. Tamper with or destroy data: Use POST /sync/reset-user-file to destructively reset the victim's sync state, POST /sync/update-user-filename to rename their budget, or POST /sync/upload-user-file to overwrite it with arbitrary content.
  3. Access encryption keys: Call POST /sync/user-get-key or POST /sync/user-create-key to read or replace the victim's encryption key, potentially enabling decryption of the stolen budget blob (Github Advisory, GitHub Security Advisory).

Indicators of compromise

  • Network: Unexpected HTTP GET requests to /sync/download-user-file or /sync/get-user-file-info with X-Actual-File-Id headers containing file IDs not associated with the authenticated user's account; POST requests to /sync/reset-user-file, /sync/update-user-filename, /sync/user-get-key, or /sync/user-create-key from users who do not own the referenced file ID.
  • Logs: Sync server access logs showing a single authenticated user (session token) accessing multiple distinct file IDs in rapid succession; requests to /sync/list-user-files by non-admin users followed immediately by requests to other users' file IDs.
  • Application Behavior: Budget files renamed unexpectedly (e.g., renamed to "pwned"); sync state reset events for files not initiated by the file owner; encryption key changes not initiated by the file owner.

Mitigation and workarounds

Upgrade @actual-app/sync-server to version 26.2.1 or later, which enforces file ownership and access checks (requireFileAccess) on all sync API endpoints and includes a database migration to backfill file owner records (GitHub Release, Patch Commit). If immediate patching is not possible, consider disabling multi-user (OpenID) mode or restricting network access to the /sync/* endpoints via a reverse proxy or firewall to trusted users only. After upgrading, review server access logs for any unauthorized cross-user file access that may have occurred prior to patching.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management