๐Ÿ” CVE Alert

CVE-2026-100392

UNKNOWN 0.0

InvoicePlane: Primary Administrator Privilege Downgrade via `Users::form()` (Missing Object-Level Authorization)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary Administrator's user_type to 2 (Guest / read-only), destroying the root account's privilege and locking the legitimate owner out of the instance. At time of publication, there are no publicly available patches.

CWE CWE-863
Vendor invoiceplane
Product invoiceplane
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for invoiceplane invoiceplane

Be the first to know when new unknown vulnerabilities affecting invoiceplane invoiceplane are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

InvoicePlane / InvoicePlane
= 1.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-4fxw-x7wr-x6qc