CVE-2026-100392: Invoiceplane

High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary Administrator's user_type to 2 (Guest / read-only), destroying the root account's privilege and locking the legitimate owner out of the instance. At time of publication, there are no publicly available patches.

Affected products

Published 2026-09-28. Last modified 2026-09-30.