CVE-2026-88003 | InvoicePlane up to 1.7.1 Session Management Users::form user_type improper authorization

SecurityVulns

A vulnerability, which was classified as problematic, was found in InvoicePlane up to 1.7.1. The affected element is the function Users::form of the component Session Management. Executing a manipulation of the argument user_type can lead to improper authorization.

This vulnerability is tracked as CVE-2026-88003. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.VulDB Recent EntriesRead More