User Account Compromise in InvoicePlane's Password Management Feature
CVE-2026-85291
6.5MEDIUM
What is CVE-2026-85291?
InvoicePlane, a popular self-hosted open source application for invoice management, has a significant security flaw in its Users::change_password() method. This vulnerability enables an authenticated secondary administrator to modify the password of the primary administrator account by simply providing a user_id in the URL, circumventing necessary authorization checks. This allows the attacker to seize control of the primary administrator's account without needing the current password, jeopardizing sensitive data and administrative privileges. This issue was addressed in version 1.7.2.
Affected Version(s)
InvoicePlane < 1.7.2
