Junglewise Threat Intelligence

CVE-2026-11942: Akaunting stored XSS in delete confirmation flow

CVE-2026-11942 · Severity: info · CVSS 4.8 · Published 2026-06-22

Technologies: Akaunting. Vendors: Akaunting.

Executive brief

Akaunting, an open-source online accounting software, is vulnerable to a security flaw where malicious code can be hidden within record names. An attacker with administrative permissions can inject scripts that execute when other users interact with the delete confirmation screen. This could allow an attacker to perform unauthorized actions or steal session information from other administrative users.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Akaunting version 3.1.21. The flaw is located in the reusable delete confirmation flow, where the application fails to properly sanitize record names (such as 'Items') before displaying them in a modal. An authenticated attacker with high privileges (permissions to create or modify records) can inject malicious HTML or JavaScript into a record name. The payload is executed in the context of any user who attempts to delete the affected record and views the confirmation prompt. This vulnerability is tracked as CWE-79.

Affected products

  • Akaunting Akaunting 3.1.21

Timeline

  • 2026-06-22: disclosed
  • 2026-06-22: advisory

References

Related threats