CVE-2026-71251

Source
https://cve.org/CVERecord?id=CVE-2026-71251
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71251.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-71251
Published
2026-08-05T10:57:11Z
Modified
2026-10-08T02:51:43Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Akaunting - Cross-Company Media IDOR in Customer Portal Download Endpoint
Details

Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download behind only generic auth middleware) fetched the requested Media record by ID with no verification that it belonged to the requesting portal customer's own company, allowing any authenticated portal customer to download any other company's uploaded files by guessing or enumerating media IDs.

Database specific
{
    "cna_assigner": "TuranSec",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71251.json"
}
References

Affected packages

Git / github.com/akaunting/akaunting

Affected ranges

Type
GIT
Repo
https://github.com/akaunting/akaunting
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
0
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

Other
0
1.*
1.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71251.json"