CVE-2026-19198: Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch
Published Aug 19, 2026
·Updated
Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkActions dispatcher.This issue affects Akaunting: 3.1.21.
Affected Software
1 affected component
Akaunting=3.1.21
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Akauntingto a version that resolves this vulnerability.Fixed in 3.1.21
Event History
Aug 19, 2026
CVE Published
via MITRE·06:58 PM
Data Sourced
via MITRE·06:58 PM
DescriptionWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is authenticated, so an attacker needs valid access to an Akaunting 3.1.21 instance before attempting exploitation.
2
Which deployments are known to be affected?
The provided information identifies Akaunting version 3.1.21 as affected. It does not specify particular deployment modes, roles, or configuration prerequisites.
3
What version information is available for remediation?
Akaunting 3.1.21 is identified as affected, and the references include the 3.2.1 release. The provided data does not explicitly state that 3.2.1 contains the fix.