CVE-2026-100392
Received Received - Intake

Privilege Escalation in InvoicePlane via User Type Manipulation

Vulnerability report for CVE-2026-100392, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary Administrator's user_type to 2 (Guest / read-only), destroying the root account's privilege and locking the legitimate owner out of the instance. At time of publication, there are no publicly available patches.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
invoiceplane invoiceplane 1.7.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

InvoicePlane 1.7.2 has an authorization flaw in Users::form() where a Secondary Administrator (user_type=1, user_id != 1) can change the Primary Administrator's user_type to 2 (Guest/read-only). This removes the Primary Administrator's privileges and locks them out of the system.

Detection Guidance

This vulnerability involves a Secondary Administrator (user_type=1, user_id != 1) exploiting a lack of authorization checks in InvoicePlane 1.7.2 to downgrade the Primary Administrator's privileges. To detect it, inspect user accounts for unexpected changes in user_type or user_id values in the database. Check for multiple accounts with user_type=1 and verify the legitimate Primary Administrator's user_id remains unchanged.

Impact Analysis

If exploited, a Secondary Administrator could take over the Primary Administrator account, gain full control of the InvoicePlane instance, and prevent the legitimate owner from accessing their own system. This could lead to data loss, unauthorized invoice or payment modifications, and disruption of billing operations.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strict access controls and audit trails for sensitive data like invoices and client information. Unauthorized privilege changes may lead to unauthorized access, data breaches, or inability to maintain proper records, potentially resulting in regulatory penalties.

Mitigation Strategies

Immediately restrict access to InvoicePlane instances to trusted users only. Review and audit all user accounts, especially those with Secondary Administrator privileges (user_type = 1). Disable or remove any unauthorized Secondary Administrator accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100392. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart