Security Vulnerability in SolidInvoice Invoicing Platform
CVE-2026-61614

5.9MEDIUM

Key Information:

Vendor
CVE Published:
4 September 2026

What is CVE-2026-61614?

SolidInvoice, an open-source invoicing solution, exposes a security risk in its REST API authentication mechanism. Prior to version 3.0.1, the authenticator allowed bearer tokens to be sent through a ?token= URL query parameter. This fallback option inadvertently records sensitive API credentials in various logs, including server access logs, browser histories, and HTTP Referer headers, creating a pathway for potential data breaches. Version 3.0.1 addresses this concern by enhancing authentication practices, thus safeguarding user information more effectively.

Affected Version(s)

SolidInvoice < 3.0.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.