PT-2026-102342 · Unknown · Invoiceplane

·

CVE-2026-100392

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions InvoicePlane version 1.7.2
Description In the Users::form() function, the application fails to perform an object-level authorization check on the user id variable when it is set to 1. This allows a Secondary Administrator to change the Primary Administrator's user type to 2 (Guest / read-only), which removes the root account's privileges and locks the legitimate owner out of the instance.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100392
GHSA-4FXW-X7WR-X6QC

Affected Products

Invoiceplane