PT-2026-97339 · Unknown · Invoiceshelf

CVE-2026-55610

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions InvoiceShelf versions prior to 2.4.1
Description In multi-company installations, a user with Owner privileges in one company can read and overwrite any user account in any other company on the same installation. This occurs because the GET/PUT /api/v1/users/{user} endpoint resolves the target user by a global primary key, and the UserPolicy function only verifies that the requester owns their own header-company without confirming if the target user belongs to that same company. This flaw enables cross-tenant disclosure of user data and full account takeover via email and password overwriting or company re-assignment.
Recommendations Update to version 2.4.1.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55610
GHSA-VGX6-6CQR-M8QR

Affected Products

Invoiceshelf