Authorization Flaw in InvoicePlane Affects User Privileges
CVE-2026-100392
7HIGH
What is CVE-2026-100392?
InvoicePlane is an open-source application designed for managing invoices and client payments. In version 1.7.2, a vulnerability exists where the Users::form() function lacks proper object-level authorization checks for user_id = 1. This allows a Secondary Administrator (user_type = 1, user_id != 1) to alter the Primary Administrator's user_type to 2, effectively downgrading their privileges to Guest (read-only) and locking the legitimate administrator out of their own account. As of now, there are no available patches for this issue, presenting significant risks to user account security and data integrity.
Affected Version(s)
InvoicePlane = 1.7.2
