Impact
Akaunting versions up to 3.1.21 allow any authenticated user with the default update-auth-profile permission to set their own role to admin by calling the UpdateUser job. The job unconditionally synchronizes the supplied roles without checking the caller's authorization, enabling privilege escalation. The attacker can then perform all actions available to an administrator, potentially altering data, configuration, and other users' permissions. This flaw is a classic access‑control weakness, corresponding to CWE‑284.
Affected Systems
The vulnerability affects Akaunting, version 3.1.21 and earlier. Users of these releases that have the update‑auth‑profile permission are at risk.
Risk and Exploitability
The flaw is not listed in CISA’s KEV catalog and no EPSS score is published. However, because it requires only low‑privileged authentication, the attack surface is significant for any compromised internal account. Exploitation is straightforward: a user simply edits their own profile to set the administrator role ID. Attacker reach is limited to users who can log into the system, so the risk is high within the affected tenant but does not enable remote code execution on the hosting environment.
OpenCVE Enrichment