PT-2026-48963 · Unknown · Actual Budget Sync-Server

CVE-2026-42604

·

Published

2026-06-12

·

Updated

2026-06-13

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Actual Budget sync-server versions prior to 26.5.0
Description The POST /openid/config endpoint exposes the complete OpenID Connect configuration, which includes the OAuth2 client secret. This information is accessible to any user who possesses the bootstrap password. Additionally, the endpoint does not implement authentication or rate limiting, allowing the bootstrap password to be discovered through brute-force attacks.
Recommendations Update to version 26.5.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42604
GHSA-49V6-PQJQ-XW55

Affected Products

Actual Budget Sync-Server