Privilege Escalation Vulnerability in InvoicePlane by InvoicePlane
CVE-2026-88003

7.5HIGH

Key Information:

Vendor
CVE Published:
25 September 2026

What is CVE-2026-88003?

InvoicePlane, a self-hosted open source application for invoice management, suffers from a privilege escalation vulnerability. This issue arises because the Admin_Controller relies on a user_type snapshot stored in an existing session, failing to revalidate a user's role after it is downgraded. Consequently, an administrator who downgrades another user's role may inadvertently leave their active session authorized for administrative privileges. The downgraded user can exploit this by invoking the Users::form() function to restore their original role, thereby restoring their elevated privileges persistently. This critical issue was addressed in version 1.7.2.

Affected Version(s)

InvoicePlane < 1.7.2

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.