A vulnerability described as problematic has been identified in Akaunting. This affects the function Download of the file app/Http/Controllers/Common/Uploads.php of the component Download. Such manipulation of the argument ID leads to improper access controls.

This vulnerability is traded as CVE-2026-71251. The attack may be launched remotely. There is no exploit available.

It is best practice to apply a patch to resolve this issue.