{"id":"CVE-2026-100371","summary":"InvoicePlane: Incomplete Authorization Remediation in Users::form() Enables Primary Administrator Account Takeover via Email Reassignment and Password Recovery","details":"InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an authorization guard to Users::change_password(), was added to address a previous authorization flaw that allowed a secondary administrator (user_type=1, user_id != 1) to directly change the password of the primary administrator (user_id=1) through users/change_password/{id}. That remediation, however, protects only the direct password-change operation. It does not protect the identity attribute that password recovery actually trusts: user_email. Users::form() applies no equivalent object-level authorization check when editing the primary administrator's account, and user_email is not included in PROTECTED_FIELDS. A secondary administrator can therefore rewrite the primary administrator's email address, then drive the public password-recovery flow — which resolves the account by user_email — to receive the reset token and take over user_id=1. The result is an alternate attack path that achieves the same impact PR #1638 was intended to prevent: cross-administrator full account takeover of the primary administrator. This issue has been patched via commit 8616fa4.","aliases":["GHSA-77hm-22wp-96wp"],"modified":"2026-10-02T03:31:08.801805770Z","published":"2026-09-28T20:15:17.155Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100371.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100371.json"},{"type":"ADVISORY","url":"https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-77hm-22wp-96wp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100371"},{"type":"FIX","url":"https://github.com/InvoicePlane/InvoicePlane/commit/8616fa45a61c1694b55bb9116e293269a0ced06a"},{"type":"FIX","url":"https://github.com/InvoicePlane/InvoicePlane/pull/1638"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/invoiceplane/invoiceplane","events":[{"introduced":"aaeea1e4825785c6138fa84be49ac373bac4f0af"},{"fixed":"8616fa45a61c1694b55bb9116e293269a0ced06a"}],"database_specific":{"extracted_events":[{"introduced":"= 1.7.2"},{"last_affected":"= 1.7.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["= 1.7.2","v1.7.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100371.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}