A vulnerability described as problematic has been identified in Akaunting. This affects the function
Download of the file app/Http/Controllers/Common/Uploads.php of the component Download. Such manipulation of the argument ID leads to improper access controls.
This vulnerability is traded as CVE-2026-71251. The attack may be launched remotely. There is no exploit available.
It is best practice to apply a patch to resolve this issue.