Plaintext API Token Vulnerability in SolidInvoice Open Source Platform
CVE-2026-46622

8.1HIGH

Key Information:

Vendor
CVE Published:
11 June 2026

What is CVE-2026-46622?

SolidInvoice, an open-source invoicing platform, has a significant security flaw where API tokens used for authenticating all REST API requests are stored as plaintext in the api_tokens database table. This means that any unauthorized user gaining read access to the database—through means such as SQL injection, leaked backups, misconfigured replicas, or insider threats—could easily obtain all API credentials for every user without any sophisticated attack methods. To mitigate this risk, a patch was issued in version 2.3.17, emphasizing the importance of upgrading to secure your instance.

Affected Version(s)

SolidInvoice < 2.3.17

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.