CVE-2026-88003 | InvoicePlane up to 1.7.1 Session Management Users::form user_type improper authorization
A vulnerability, which was classified as problematic, was found in InvoicePlane up to 1.7.1. The affected element is the function Users::form of the component Session Management. Executing a manipulation of the argument user_type can lead to improper authorization.
This vulnerability is tracked as CVE-2026-88003. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.VulDB Recent EntriesRead More