Open-Source Invoicing Platform Vulnerability in SolidInvoice
CVE-2026-61608

6.8MEDIUM

Key Information:

Vendor
CVE Published:
4 September 2026

What is CVE-2026-61608?

SolidInvoice, a widely used open-source invoicing platform, contains a security flaw where 'UserInvitation' entities lack an expiry timestamp. This oversight allows invitation links sent to users to remain valid indefinitely. Consequently, if an invitation email is leaked, forwarded, or archived, it could be exploited at any time to gain unauthorized access to the platform. This vulnerability poses a significant risk as it enables malicious actors to join a company or add a compromised account without detection. The issue was resolved in version 3.0.1, which includes measures to ensure that invitation links expire as intended.

Affected Version(s)

SolidInvoice < 3.0.1

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.