Actualbudget · Actual · CVE-2026-50007
**Name of the Vulnerable Software and Affected Versions**
Actual versions prior to 26.7.0
**Description**
A missing authorization issue allows a shared user with `user access` on a budget file to perform file management actions reserved for the owner or an administrator. This occurs because the `requireFileAccess()` function incorrectly treats standard shared access as sufficient for high-privilege operations. An attacker can exploit this by calling the following API endpoints: '/delete-user-file', '/reset-user-file', and '/user-create-key'.
**Recommendations**
Update to version 26.7.0.