Privilege Escalation Vulnerability in InvoicePlane by InvoicePlane
CVE-2026-88003
7.5HIGH
What is CVE-2026-88003?
InvoicePlane, a self-hosted open source application for invoice management, suffers from a privilege escalation vulnerability. This issue arises because the Admin_Controller relies on a user_type snapshot stored in an existing session, failing to revalidate a user's role after it is downgraded. Consequently, an administrator who downgrades another user's role may inadvertently leave their active session authorized for administrative privileges. The downgraded user can exploit this by invoking the Users::form() function to restore their original role, thereby restoring their elevated privileges persistently. This critical issue was addressed in version 1.7.2.
Affected Version(s)
InvoicePlane < 1.7.2
