CVE-2026-100371 Details
Description
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an authorization guard to Users::change_password(), was added to address a previous authorization flaw that allowed a secondary administrator (user_type=1, user_id != 1) to directly change the password of the primary administrator (user_id=1) through users/change_password/{id}. That remediation, however, protects only the direct password-change operation. It does not protect the identity attribute that password recovery actually trusts: user_email. Users::form() applies no equivalent object-level authorization check when editing the primary administrator's account, and user_email is not included in PROTECTED_FIELDS. A secondary administrator can therefore rewrite the primary administrator's email address, then drive the public password-recovery flow — which resolves the account by user_email — to receive the reset token and take over user_id=1. The result is an alternate attack path that achieves the same impact PR #1638 was intended to prevent: cross-administrator full account takeover of the primary administrator. This issue has been patched via commit 8616fa4.
A vulnerability in InvoicePlane version 1.7.2 allows a secondary administrator to take over the primary administrator's account by exploiting an incomplete authorization check. The issue arises because the 'user_email' field, which is crucial for the password recovery process, is not properly protected. A secondary administrator can change the primary administrator's email to one they control, then use the password reset feature to gain access to the account. This vulnerability effectively bypasses the intended protections put in place by a previous update, restoring a path for full account takeover.
The vulnerability has been patched in the latest version. Users should update to the version that includes the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-77hm-22wp-96wp | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/InvoicePlane/InvoicePlane/commit/8616fa45a61c1694b55bb9116e293269a0ced06a | [email protected] | Source CodeVendor |
| https://github.com/InvoicePlane/InvoicePlane/pull/1638 | [email protected] | Issue TrackingVendor |
| https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-77hm-22wp-96wp | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| InvoicePlane | 1.7.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion