Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Akaunting
Akaunting akaunting |
|
| Weaknesses | CWE-284 | |
| Vendors & Products |
Akaunting
Akaunting akaunting |
Fri, 14 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` job, which processes user-supplied role assignments via an unconditional `roles()->sync()` call without verifying whether the caller is authorized to manage roles. Users only require the default `update-auth-profile` permission to access the self-update path and assign themselves as admins. The API endpoints are properly permission‑gated and are not affected by this issue. | |
| Title | CVE-2026-16772 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-08-14T15:18:13.993Z
Reserved: 2026-07-23T16:56:04.052Z
Link: CVE-2026-16772
No data.
Status : Received
Published: 2026-08-14T16:16:50.290
Modified: 2026-08-14T16:16:50.290
Link: CVE-2026-16772
No data.
OpenCVE Enrichment
Updated: 2026-08-14T16:30:05Z