Skip to content

Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers

High severity GitHub Reviewed Published Apr 23, 2026 in actualbudget/actual • Updated Apr 27, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts