CVE-2026-88003: InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade

Published Sep 25, 2026
·
Updated

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privileges after a role downgrade because AdminController trusts the usertype snapshot stored in an existing session instead of revalidating ipusers.usertype. When one administrator downgrades another account, the target's active session continues to authorize administrative requests. The downgraded user can use Users::form() to set usertype back to 1, restoring the database role and making the privilege escalation persistent. This vulnerability is fixed in 1.7.2.

Affected Software

1 affected component
InvoicePlane InvoicePlane<1.7.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade InvoicePlane to a version that resolves this vulnerability.

    Fixed in 1.7.2

Event History

Sep 25, 2026
CVE Published
via MITRE·09:20 PM
Data Sourced
via MITRE·09:20 PM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

InvoicePlane deployments running versions before 1.7.2 are affected when an administrator downgrades an account that still has an active session. The downgraded account can retain administrative authorization through that existing session.

2

What must an attacker have to exploit it?

The attacker must be a user whose account previously had administrative privileges, must have an active session created while that role was assigned, and must then be downgraded by another administrator. They can use the retained authorization to change their user_type back to 1.

3

How can administrators tell whether a downgrade may have been bypassed?

Review accounts that were downgraded while logged in and determine whether their sessions remained active afterward. Affected accounts may have had their database role restored to user_type 1 through Users::form().

4

What can be done if upgrading is not immediately possible?

Ensure that users whose administrative roles are downgraded do not retain active sessions, since the issue depends on an existing session retaining the prior user_type snapshot. Upgrade to InvoicePlane 1.7.2 to apply the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203