Plaintext API Token Vulnerability in SolidInvoice Open Source Platform
CVE-2026-46622
8.1HIGH
What is CVE-2026-46622?
SolidInvoice, an open-source invoicing platform, has a significant security flaw where API tokens used for authenticating all REST API requests are stored as plaintext in the api_tokens database table. This means that any unauthorized user gaining read access to the database—through means such as SQL injection, leaked backups, misconfigured replicas, or insider threats—could easily obtain all API credentials for every user without any sophisticated attack methods. To mitigate this risk, a patch was issued in version 2.3.17, emphasizing the importance of upgrading to secure your instance.
Affected Version(s)
SolidInvoice < 2.3.17
