CVE-2026-43872: Actualbudget Actual
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Version 26.5.0 fixes the issue.
Affected products
- Actualbudget Actual: before 26.5.0 (fixed in 26.5.0)
Published 2026-06-12. Last modified 2026-06-17.