CVE-2026-100392
InvoicePlane: Primary Administrator Privilege Downgrade via `Users::form()` (Missing Object-Level Authorization)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary Administrator's user_type to 2 (Guest / read-only), destroying the root account's privilege and locking the legitimate owner out of the instance. At time of publication, there are no publicly available patches.
| CWE | CWE-863 |
| Vendor | invoiceplane |
| Product | invoiceplane |
| Published | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for invoiceplane invoiceplane
Be the first to know when new unknown vulnerabilities affecting invoiceplane invoiceplane are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
InvoicePlane / InvoicePlane
= 1.7.2