๐Ÿ” CVE Alert

CVE-2026-88003

UNKNOWN 0.0

InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privileges after a role downgrade because Admin_Controller trusts the user_type snapshot stored in an existing session instead of revalidating ip_users.user_type. When one administrator downgrades another account, the target's active session continues to authorize administrative requests. The downgraded user can use Users::form() to set user_type back to 1, restoring the database role and making the privilege escalation persistent. This vulnerability is fixed in 1.7.2.

CWE CWE-863
Vendor invoiceplane
Product invoiceplane
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for invoiceplane invoiceplane

Be the first to know when new unknown vulnerabilities affecting invoiceplane invoiceplane are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

InvoicePlane / InvoicePlane
< 1.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-25xj-pj36-wpp8 github.com: https://github.com/InvoicePlane/InvoicePlane/commit/904847f4e87b66fd6743cf9cc6f88b66c7fc3b81 github.com: https://github.com/InvoicePlane/InvoicePlane/commit/daa49ce3a50e0c93e01459b69c0d61bfc23d23eb github.com: https://github.com/InvoicePlane/InvoicePlane/releases/tag/v1.7.2