{"id":"CVE-2026-100392","published":"2026-09-28T21:17:11.827","lastModified":"2026-09-29T20:17:10.727","description":"InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary Administrator's user_type to 2 (Guest / read-only), destroying the root account's privilege and locking the legitimate owner out of the instance. At time of publication, there are no publicly available patches.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-863"],"vendors":[],"products":[],"references":[{"url":"https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-4fxw-x7wr-x6qc","tags":[]},{"url":"https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-4fxw-x7wr-x6qc","tags":[]}],"exploitRefs":[{"url":"https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-4fxw-x7wr-x6qc","tags":[]},{"url":"https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-4fxw-x7wr-x6qc","tags":[]}],"hasPoc":true,"ai":null}