CVE-2026-3089: Actual Sync Server 26.2.1 - Authenticated Path Traversal
Description
Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to 26.3.0, improper validation of the user-controlled x-actual-file-id header means that traversal segments (../) can escape the intended directory and write files outside userFiles.
Mitigations The vulnerability can be mitigated in prior versions by running the sync server in a filesystem sandbox.
Other sources
Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to 26.3.0, improper validation of the user-controlled x-actual-file-id header means that traversal segments (../) can escape the intended directory and write files outside userFiles.This issue affects prior versions of Actual Sync Server 26.3.0.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3089?
CVE-2026-3089 has been classified as a high severity vulnerability due to the risk of authenticated path traversal.
How do I fix CVE-2026-3089?
To fix CVE-2026-3089, upgrade to Actual Sync Server version 26.3.0 or later, which addresses the path traversal issue.
What type of vulnerability is CVE-2026-3089?
CVE-2026-3089 is an authenticated path traversal vulnerability that allows users to manipulate file pathways.
Who is affected by CVE-2026-3089?
All versions of Actual Sync Server prior to 26.3.0 are affected by CVE-2026-3089.
What methods can be exploited in CVE-2026-3089?
The vulnerability in CVE-2026-3089 can be exploited through the x-actual-file-id header when uploading files.