{"api_version":"1","generated_at":"2026-08-14T17:46:21+00:00","cve":"CVE-2026-16772","urls":{"html":"https://cve.report/CVE-2026-16772","api":"https://cve.report/api/cve/CVE-2026-16772.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-16772","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-16772"},"summary":{"title":"CVE-2026-16772","description":"In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` job, which processes user-supplied role assignments via an unconditional `roles()->sync()` call without verifying whether the caller is authorized to manage roles. Users only require the default `update-auth-profile` permission to access the self-update path and assign themselves as admins. The API endpoints are properly permission‑gated and are not affected by this issue.","state":"PUBLISHED","assigner":"certcc","published_at":"2026-08-14 16:16:50","updated_at":"2026-08-14 16:16:50"},"problem_types":["CWE-862 Missing Authorization","CWE-269 Improper Privilege Management"],"metrics":[],"references":[{"url":"https://vokecyber.com/research/cve-2026-16772-akaunting-privilege-escalation","name":"https://vokecyber.com/research/cve-2026-16772-akaunting-privilege-escalation","refsource":"cret@cert.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16772","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16772","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Akaunting","product":"Akaunting","version":"affected 3.1.21 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"product":"Akaunting","vendor":"Akaunting","versions":[{"lessThanOrEqual":"3.1.21","status":"affected","version":"0","versionType":"custom"}]}],"descriptions":[{"lang":"en","value":"In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` job, which processes user-supplied role assignments via an unconditional `roles()->sync()` call without verifying whether the caller is authorized to manage roles. Users only require the default `update-auth-profile` permission to access the self-update path and assign themselves as admins. The API endpoints are properly permission‑gated and are not affected by this issue."}],"problemTypes":[{"descriptions":[{"description":"CWE-862 Missing Authorization","lang":"en"}]},{"descriptions":[{"description":"CWE-269 Improper Privilege Management","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2026-08-14T15:18:13.993Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"url":"https://vokecyber.com/research/cve-2026-16772-akaunting-privilege-escalation"}],"source":{"discovery":"UNKNOWN"},"title":"CVE-2026-16772","x_generator":{"engine":"VINCE 3.0.44","env":"prod","origin":"https://cveawg.mitre.org/api/cve/CVE-2026-16772"}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2026-16772","datePublished":"2026-08-14T15:18:13.993Z","dateReserved":"2026-07-23T16:56:04.052Z","dateUpdated":"2026-08-14T15:18:13.993Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-14 16:16:50","lastModifiedDate":"2026-08-14 16:16:50","problem_types":["CWE-862 Missing Authorization","CWE-269 Improper Privilege Management"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"16772","Ordinal":"1","Title":"CVE-2026-16772","CVE":"CVE-2026-16772","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"16772","Ordinal":"1","NoteData":"In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` job, which processes user-supplied role assignments via an unconditional `roles()->sync()` call without verifying whether the caller is authorized to manage roles. Users only require the default `update-auth-profile` permission to access the self-update path and assign themselves as admins. The API endpoints are properly permission‑gated and are not affected by this issue.","Type":"Description","Title":"CVE-2026-16772"}]}}}