OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-88003

HIGH · CVSS 7.5 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

InvoicePlane versions prior to 1.7.2 are vulnerable due to improper handling of user role downgrades, allowing downgraded administrators to retain administrative privileges through active sessions. This flaw can lead to unauthorized access and persistent privilege escalation, posing a significant risk to the integrity of the application. Organizations using InvoicePlane should prioritize upgrading to version 1.7.2 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88003
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privileges after a role downgrade because Admin_Controller trusts the user_type snapshot stored in an existing session instead of revalidating ip_users.user_type. When one administrator downgrades another account, the target's active session continues to authorize administrative requests. The downgraded user can use Users::form() to set user_type back to 1, restoring the database role and making the privilege escalation persistent. This vulnerability is fixed in 1.7.2.