CVE-2026-100392

CVE-2026-100392 published: InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewr...

View full NVD advisory → ← Back to CVE watch