PT-2026-97339 · Unknown · Invoiceshelf
CVE-2026-55610
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
InvoiceShelf versions prior to 2.4.1
Description
In multi-company installations, a user with Owner privileges in one company can read and overwrite any user account in any other company on the same installation. This occurs because the
GET/PUT /api/v1/users/{user} endpoint resolves the target user by a global primary key, and the UserPolicy function only verifies that the requester owns their own header-company without confirming if the target user belongs to that same company. This flaw enables cross-tenant disclosure of user data and full account takeover via email and password overwriting or company re-assignment.Recommendations
Update to version 2.4.1.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invoiceshelf