CVE-2026-61608
Received Received - Intake

Persistent Invitation Links in SolidInvoice Prior to 3.0.1

Vulnerability report for CVE-2026-61608, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: GitHub, Inc.

Description

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning a leaked, forwarded, or archived invitation email can be used at any time in the future to join a company or silently add a compromised email account to a company. Version 3.0.1 fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
solidinvoice solidinvoice to 3.0.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects SolidInvoice, an open-source invoicing platform. UserInvitation entities lack an expiry timestamp, meaning invitation links sent to users never expire. If such a link is leaked, forwarded, or archived, it can be used at any future time to join a company or add a compromised email account without detection.

Detection Guidance

Check SolidInvoice user invitation links for expiry timestamps. Review database entries for UserInvitation entities to confirm if expiry fields exist and are populated. Inspect email archives or forwarded invitations for links that lack expiration.

Impact Analysis

An attacker could exploit this by obtaining a valid invitation link through methods like email interception or forwarding. This allows unauthorized access to a company's SolidInvoice instance, potentially leading to data theft, fraudulent invoices, or unauthorized account creation.

Compliance Impact

This vulnerability may violate compliance requirements for data protection and access control. GDPR requires timely revocation of access and protection against unauthorized access. HIPAA mandates strict access controls and audit trails. The lack of expiry on invitations could lead to unauthorized access, breaching these standards.

Mitigation Strategies

Upgrade SolidInvoice to version 3.0.1 or later to enable invitation expiry. Review and revoke all existing user invitations. Audit company memberships for unauthorized accounts added via old invitations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61608. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart