Impact
The vulnerability allows authenticated users to trigger bulk operations without proper authorization checks, enabling them to perform actions beyond their intended permissions. This flaw exposes the application to integrity and confidentiality risks as sensitive data can be altered or accessed unlawfully. It is classified as a CWE‑863 authorization weakness.
Affected Systems
Akaunting 3.1.21 is affected on Linux, macOS, and Windows platforms. The issue specifically targets the BulkActions dispatcher in this version.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score is not available, implying limited current exploitation data. The vulnerability is not listed in the CISA KEV catalog, though the lack of a KEV listing does not reduce its potential impact. The attack vector is inferred to require an authenticated session with a user role that has some level of access to bulk operations; the absence of an explicit authorization check permits escalation of privileges or unauthorized data manipulation.
OpenCVE Enrichment