User Account Compromise in InvoicePlane's Password Management Feature
CVE-2026-85291

6.5MEDIUM

Key Information:

Vendor
CVE Published:
25 September 2026

What is CVE-2026-85291?

InvoicePlane, a popular self-hosted open source application for invoice management, has a significant security flaw in its Users::change_password() method. This vulnerability enables an authenticated secondary administrator to modify the password of the primary administrator account by simply providing a user_id in the URL, circumventing necessary authorization checks. This allows the attacker to seize control of the primary administrator's account without needing the current password, jeopardizing sensitive data and administrative privileges. This issue was addressed in version 1.7.2.

Affected Version(s)

InvoicePlane < 1.7.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.