Security Vulnerability in SolidInvoice Invoicing Platform
CVE-2026-61614
5.9MEDIUM
What is CVE-2026-61614?
SolidInvoice, an open-source invoicing solution, exposes a security risk in its REST API authentication mechanism. Prior to version 3.0.1, the authenticator allowed bearer tokens to be sent through a ?token= URL query parameter. This fallback option inadvertently records sensitive API credentials in various logs, including server access logs, browser histories, and HTTP Referer headers, creating a pathway for potential data breaches. Version 3.0.1 addresses this concern by enhancing authentication practices, thus safeguarding user information more effectively.
Affected Version(s)
SolidInvoice < 3.0.1
