PT-2026-99129 · Unknown · Invoiceplane

CVE-2026-88003

·

Published

2026-09-25

·

Updated

2026-09-26

CVSS v4.0

7.5

High

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions InvoicePlane versions prior to 1.7.2
Description InvoicePlane fails to revoke administrative privileges immediately after a role downgrade. This occurs because the Admin Controller relies on the user type snapshot stored in an active session rather than revalidating the user type within the ip users table. Consequently, a user whose privileges have been downgraded can still authorize administrative requests during their current session. Furthermore, the downgraded user can utilize the Users::form() function to change their user type back to 1, making the privilege escalation persistent.
Recommendations Update to version 1.7.2.

Exploit

Fix

LPE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88003
GHSA-25XJ-PJ36-WPP8

Affected Products

Invoiceplane