CVE-2026-46622: SolidInvoice: API tokens stored as plaintext in the database allowing full credential compromise on database breach

Published Jun 11, 2026
·
Updated

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the apitokens database table. Any attacker who obtains read access to the database — through SQL injection, a leaked backup, a misconfigured replica, or insider access — immediately obtains all API credentials for every user with no further effort. This issue has been patched in version 2.3.17.

Affected Software

1 affected component
SolidInvoice SolidInvoice<2.3.17

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SolidInvoice to a version that resolves this vulnerability.

    Fixed in 2.3.17
  2. Compensating control

    Restrict and monitor read access to the database (including backups and replicas), remediate SQL injection vulnerabilities, and limit insider access so that unauthorized parties cannot obtain database read access.

  3. Operational

    Rotate and invalidate all API tokens/credentials after applying the fix to ensure any tokens that may have been exposed via database read access are no longer valid.

Event History

Jun 11, 2026
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-46622?

The severity of CVE-2026-46622 is rated as high with a score of 8.1.

2

How do I fix CVE-2026-46622?

To fix CVE-2026-46622, upgrade SolidInvoice to version 2.3.17 or later.

3

What risks are associated with CVE-2026-46622?

CVE-2026-46622 poses the risk of full credential compromise if an attacker gains access to the database.

4

What specific vulnerability does CVE-2026-46622 exploit?

CVE-2026-46622 exploits the storage of API tokens as plaintext in the database.

5

What can cause an attacker to access the database related to CVE-2026-46622?

An attacker can access the database through vulnerabilities like SQL injection, leaked backups, or misconfigurations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203