CVE-2026-100371 - InvoicePlane: Incomplete Authorization Remediation in Users::form() Enables Primary Administrator Account Takeover via Email Reassignment and Password Recovery
CVE ID :CVE-2026-100371 Published : Sept. 28, 2026, 9:17 p.m. | 58 minutes ago Description :InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an authorization guard to Users::change_password(), was added to address a previous...