
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27638 is a missing authorization vulnerability in Actual Budget's sync server (@actual-app/sync-server) that allows any authenticated user in multi-user (OpenID) mode to read, modify, and overwrite other users' budget files by supplying an arbitrary file ID. It affects all versions of @actual-app/sync-server up to and including 26.2.0 (npm package). The vulnerability was published on February 26, 2026, and patched in version 26.2.1. It carries a CVSS v3.1 base score of 7.1 (High) and a CVSS v4.0 base score of 5.7 (Medium) (Github Advisory, GitHub Security Advisory).
The root cause is CWE-862 (Missing Authorization) in packages/sync-server/src/app-sync.ts. The validateSessionMiddleware (line 31) confirms that a user is authenticated, and individual sync endpoints call verifyFileExists to confirm the file exists — but neither check verifies that the requesting user owns or has been granted access to the file. The only endpoint that correctly enforced ownership was POST /sync/delete-user-file, which compared file.owner === userId and checked isAdmin(userId). This ownership check was absent from eight other endpoints: GET /sync/download-user-file, POST /sync/upload-user-file, POST /sync/sync, POST /sync/user-get-key, POST /sync/user-create-key, POST /sync/reset-user-file, POST /sync/update-user-filename, and GET /sync/get-user-file-info. An attacker needs only a valid session token and a target file ID (discoverable via admin listing, shared access records, or enumeration) to exploit any of these endpoints (Github Advisory, GitHub Security Advisory).
In multi-user OpenID deployments, a malicious authenticated user can exfiltrate complete financial data from any other user's budget — including transactions, account balances, payees, and encryption key material — by downloading their budget file. Beyond data theft, the attacker can overwrite or corrupt budget files, reset sync state (a destructive operation), rename files, and tamper with encryption keys, resulting in permanent data loss or integrity compromise for victims. Because Actual is a personal finance application, the exposed data is highly sensitive and the integrity impact is severe (Github Advisory).
A proof-of-concept is publicly documented in the GitHub Security Advisory, demonstrating exploitation via simple curl commands requiring only a valid session token and a target file ID. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.036–0.039% (12th percentile), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Github Advisory, GitHub Security Advisory).
GET /sync/list-user-files. Alternatively, file IDs may be discoverable through user_access sharing records or by guessing/brute-forcing UUID-format IDs./sync/download-user-file with the victim's file ID in the X-Actual-File-Id header and the attacker's session token in X-Actual-Token:curl -X GET 'https://actual.example.com/sync/download-user-file' \
-H 'X-Actual-Token: <attacker_token>' \
-H 'X-Actual-File-Id: <victim_file_id>' \
-o stolen-budget.blobGET /sync/get-user-file-info with the victim's file ID to retrieve metadata about the budget.POST /sync/reset-user-file to destructively reset the victim's sync state, POST /sync/update-user-filename to rename their budget, or POST /sync/upload-user-file to overwrite it with arbitrary content.POST /sync/user-get-key or POST /sync/user-create-key to read or replace the victim's encryption key, potentially enabling decryption of the stolen budget blob (Github Advisory, GitHub Security Advisory)./sync/download-user-file or /sync/get-user-file-info with X-Actual-File-Id headers containing file IDs not associated with the authenticated user's account; POST requests to /sync/reset-user-file, /sync/update-user-filename, /sync/user-get-key, or /sync/user-create-key from users who do not own the referenced file ID./sync/list-user-files by non-admin users followed immediately by requests to other users' file IDs.Upgrade @actual-app/sync-server to version 26.2.1 or later, which enforces file ownership and access checks (requireFileAccess) on all sync API endpoints and includes a database migration to backfill file owner records (GitHub Release, Patch Commit). If immediate patching is not possible, consider disabling multi-user (OpenID) mode or restricting network access to the /sync/* endpoints via a reverse proxy or firewall to trusted users only. After upgrading, review server access logs for any unauthorized cross-user file access that may have occurred prior to patching.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."