PT-2026-48963 · Unknown · Actual Budget Sync-Server
CVE-2026-42604
·
Published
2026-06-12
·
Updated
2026-06-13
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions
Actual Budget sync-server versions prior to 26.5.0
Description
The
POST /openid/config endpoint exposes the complete OpenID Connect configuration, which includes the OAuth2 client secret. This information is accessible to any user who possesses the bootstrap password. Additionally, the endpoint does not implement authentication or rate limiting, allowing the bootstrap password to be discovered through brute-force attacks.Recommendations
Update to version 26.5.0.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Actual Budget Sync-Server