CVE-2026-100371
Received Received - Intake

Authorization Bypass in InvoicePlane via Email Change

Vulnerability report for CVE-2026-100371, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an authorization guard to Users::change_password(), was added to address a previous authorization flaw that allowed a secondary administrator (user_type=1, user_id != 1) to directly change the password of the primary administrator (user_id=1) through users/change_password/{id}. That remediation, however, protects only the direct password-change operation. It does not protect the identity attribute that password recovery actually trusts: user_email. Users::form() applies no equivalent object-level authorization check when editing the primary administrator's account, and user_email is not included in PROTECTED_FIELDS. A secondary administrator can therefore rewrite the primary administrator's email address, then drive the public password-recovery flow β€” which resolves the account by user_email β€” to receive the reset token and take over user_id=1. The result is an alternate attack path that achieves the same impact PR #1638 was intended to prevent: cross-administrator full account takeover of the primary administrator. This issue has been patched via commit 8616fa4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
invoiceplane invoiceplane 1.7.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in InvoicePlane 1.7.2 allows a secondary administrator to take over the primary administrator's account. The issue involves bypassing an authorization check by changing the primary admin's email address, then using the password recovery feature to reset the password and gain full control.

Detection Guidance

This vulnerability involves a secondary administrator exploiting the user_email field to bypass password recovery protections. To detect it, inspect InvoicePlane logs for unauthorized email changes to the primary administrator account (user_id=1). Check for POST requests to users/change_password/{id} or users/form() with modified user_email values targeting user_id=1.

Impact Analysis

If exploited, this vulnerability allows a secondary admin to fully compromise the primary admin's account, gaining access to sensitive invoice, client, and payment data. This could lead to unauthorized transactions, data theft, or system misuse.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations using InvoicePlane may face compliance violations and legal penalties.

Mitigation Strategies

Update InvoicePlane to the latest patched version to address the authorization flaw in user_email handling and password recovery.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100371. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart