CVE-2026-100392 Details
Description
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary Administrator's user_type to 2 (Guest / read-only), destroying the root account's privilege and locking the legitimate owner out of the instance. At time of publication, there are no publicly available patches.
A vulnerability in InvoicePlane version 1.7.2 allows a Secondary Administrator to downgrade the Primary Administrator's privileges, effectively locking them out of the application. This issue arises because the 'Users::form()' function does not perform proper authorization checks on the Primary Administrator's user ID. As a result, a Secondary Administrator can change the Primary Administrator's user type to 'Guest', removing their administrative rights. This vulnerability is compounded by the fact that there are no available patches at this time.
The recommended remediation is to implement a global object-level authorization check in the 'Users::form()' method to prevent any modifications to the Primary Administrator's attributes by Secondary Administrators. This guard should be placed before any validation or data processing to ensure that the Primary Administrator's privileges are protected during all user management operations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-4fxw-x7wr-x6qc | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-4fxw-x7wr-x6qc | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| InvoicePlane | 1.7.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion