Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Invoiceshelf
Invoiceshelf invoiceshelf |
|
| Vendors & Products |
Invoiceshelf
Invoiceshelf invoiceshelf |
Wed, 23 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.4.1, in InvoiceShelf's multi-company installations, any user who is an Owner of one company can read and overwrite any user account in any other company on the same installation. `GET/PUT /api/v1/users/{user}` resolves the target `User` by global primary key, and `UserPolicy` checks only that the requester owns their own header-company — it never verifies that the target user belongs to that company. This allows cross-tenant disclosure of user data and full account takeover (email/password overwrite + company re-assignment). Version 2.4.1 fixes the issue. | |
| Title | InvoiceShelf has cross-company user read/update IDOR that enables cross-tenant account takeover | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-23T19:44:59.636Z
Reserved: 2026-06-16T23:31:22.445Z
Link: CVE-2026-55610
Updated: 2026-09-23T18:14:06.514Z
Status : Awaiting Analysis
Published: 2026-09-23T15:17:14.580
Modified: 2026-09-23T20:17:11.580
Link: CVE-2026-55610
No data.
OpenCVE Enrichment
Updated: 2026-09-23T17:00:08Z