Junglewise Threat Intelligence

CVE-2026-39901: monetr improper authorization in transaction update endpoint

CVE-2026-39901 · Severity: medium · CVSS 5.7 · Published 2026-04-08

Technologies: github.com/monetr/monetr (Go). Vendors: Go.

Executive brief

monetr is a budgeting application used to track and plan recurring expenses. A flaw in the software allows users to bypass restrictions and hide or 'soft-delete' imported financial transactions that are supposed to be permanent. This can lead to inaccurate financial records, compromised bookkeeping integrity, and the loss of a reliable audit trail for synced expenses.

Technical details

The vulnerability is an improper authorization and integrity flaw (CWE-285) within the transaction update (PUT) path. While the application correctly blocks the deletion of synced transactions via the dedicated DELETE handler, the PUT endpoint fails to filter server-managed fields. An authenticated attacker can submit a full Transaction object containing a user-supplied 'deletedAt' value. The server persists this field, effectively soft-deleting the record and hiding it from standard views. This bypasses the immutability policy intended for imported transaction records. The issue is resolved in version 1.12.3.

Affected products

  • monetr monetr < 1.12.3

Timeline

  • 2026-04-07: advisory: GitHub Security Advisory published
  • 2026-04-08: disclosed: CVE-2026-39901 published
  • 2026-04-08: patched: Fix released in version 1.12.3

References

Related threats