Authorization Flaw in InvoicePlane Affects User Privileges
CVE-2026-100392

7HIGH

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-100392?

InvoicePlane is an open-source application designed for managing invoices and client payments. In version 1.7.2, a vulnerability exists where the Users::form() function lacks proper object-level authorization checks for user_id = 1. This allows a Secondary Administrator (user_type = 1, user_id != 1) to alter the Primary Administrator's user_type to 2, effectively downgrading their privileges to Guest (read-only) and locking the legitimate administrator out of their own account. As of now, there are no available patches for this issue, presenting significant risks to user account security and data integrity.

Affected Version(s)

InvoicePlane = 1.7.2

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.