Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 CWE-862 |
|
| Metrics |
cvssV3_1
|
Fri, 14 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Akaunting
Akaunting akaunting |
|
| Weaknesses | CWE-284 | |
| Vendors & Products |
Akaunting
Akaunting akaunting |
Fri, 14 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` job, which processes user-supplied role assignments via an unconditional `roles()->sync()` call without verifying whether the caller is authorized to manage roles. Users only require the default `update-auth-profile` permission to access the self-update path and assign themselves as admins. The API endpoints are properly permission‑gated and are not affected by this issue. | |
| Title | CVE-2026-16772 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-08-14T19:48:54.056Z
Reserved: 2026-07-23T16:56:04.052Z
Link: CVE-2026-16772
Updated: 2026-08-14T19:48:48.203Z
Status : Received
Published: 2026-08-14T16:16:50.290
Modified: 2026-08-14T20:16:49.563
Link: CVE-2026-16772
No data.
OpenCVE Enrichment
Updated: 2026-08-14T16:30:05Z