Authorization Flaw in InvoicePlane Allows Account Takeover
CVE-2026-100371
8.7HIGH
What is CVE-2026-100371?
In InvoicePlane version 1.7.2, a flaw exists that allows secondary administrators to bypass protections put in place to prevent them from changing the primary administrator's email address. While a recent patch aimed to secure password changes, it failed to address the absence of checks on critical account attributes, specifically the user_email field. Consequently, a secondary administrator can alter the primary administrator's email, enabling them to initiate a password recovery process and seize control of the primary account. This oversight presents a significant security risk, allowing unauthorized access and manipulation of administrative privileges.
Affected Version(s)
InvoicePlane = 1.7.2
