CVE-2026-11994: Akaunting 3.1.21 - Authenticated stored XSS in report description rendering
Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. A user with permission to create or update reports can store arbitrary HTML/JavaScript in the description field of a report.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict the account permission to create or update reports to trusted administrative users only (remove or revoke the 'create or update reports' permission from untrusted roles/accounts and enforce via RBAC/policy).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11994?
The severity of CVE-2026-11994 is medium with a CVSS score of 4.8.
How do I fix CVE-2026-11994?
To fix CVE-2026-11994, update to the latest version of Akaunting that addresses the authenticated stored XSS vulnerability.
What does CVE-2026-11994 exploit?
CVE-2026-11994 exploits an authenticated stored Cross-Site Scripting vulnerability in the report description rendering.
Who can be affected by CVE-2026-11994?
Users with permission to create or update reports in Akaunting 3.1.21 can be affected by CVE-2026-11994.
What type of vulnerability is CVE-2026-11994?
CVE-2026-11994 is a Cross-Site Scripting (XSS) vulnerability.