CVE-2026-61608 Overview
CVE-2026-61608 is an insufficient session expiration vulnerability in SolidInvoice, an open-source invoicing platform. Versions prior to 3.0.1 create UserInvitation entities without an expiry timestamp. Invitation links emailed to users therefore remain valid indefinitely. An attacker who obtains a leaked, forwarded, or archived invitation email can redeem the link at any point in the future to join a target company or silently attach a compromised email account to that company. The vulnerability is tracked under [CWE-613: Insufficient Session Expiration]. SolidInvoice 3.0.1 addresses the flaw.
Critical Impact
Attackers with access to old invitation emails can join a SolidInvoice company account long after the invitation was issued, gaining unauthorized access to invoicing data.
Affected Products
- SolidInvoice versions prior to 3.0.1
- SolidInvoice UserInvitation entity workflow
- Deployments relying on emailed invitation links for user onboarding
Discovery Timeline
- 2026-09-04 - CVE-2026-61608 published to NVD
- 2026-09-10 - Last updated in NVD database
Technical Details for CVE-2026-61608
Vulnerability Analysis
SolidInvoice issues invitation tokens to onboard new users into a company workspace. Prior to version 3.0.1, the UserInvitation entity omits any expiration field. The application accepts an invitation token as valid whenever it is presented, regardless of how much time has elapsed since issuance.
This breaks a core assumption of email-based onboarding flows: that invitation links are short-lived, single-purpose credentials. Because the token has no bounded lifetime, its exposure surface expands to every mail archive, backup, forwarding rule, and downstream mailbox that ever received the message.
Exploitation requires the attacker to obtain the invitation email and to convince a user (or themselves) to click the link, which is why the CVSS vector notes user interaction and higher attack complexity. Successful redemption grants membership in the target company with the role encoded in the invitation.
Root Cause
The root cause is a missing temporal control on authentication artifacts, classified as [CWE-613]. The UserInvitation schema does not persist an expiresAt timestamp, and the redemption code path performs no time-based validation. Any policy that assumes an invitation link is only usable for a limited window is silently violated.
Attack Vector
The attack is remote and network-based. An adversary needs read access to a historical invitation email through a compromised mailbox, mail server backup, unencrypted archive, or a misdirected forward. The attacker then submits the invitation token to the SolidInvoice instance through the normal acceptance workflow. If the invitation was issued to an address the attacker now controls, they can bind that address to the company without further interaction from administrators.
Refer to the GitHub Security Advisory GHSA-5gcp-fm29-jgrp for vendor-authored technical details.
Detection Methods for CVE-2026-61608
Indicators of Compromise
- Successful acceptance of UserInvitation records whose creation timestamp is weeks or months old.
- New company memberships bound to email addresses that were previously deactivated or reassigned.
- Redemption of invitation tokens from IP addresses or user agents that do not match the original invitee.
Detection Strategies
- Query the SolidInvoice database for UserInvitation rows joined against acceptance events and flag deltas above an acceptable onboarding window, for example greater than 7 days.
- Correlate invitation-accepted events with recent mailbox compromise indicators for the invitee address.
- Alert on repeated invitation acceptances tied to the same company from disparate geographies.
Monitoring Recommendations
- Ship SolidInvoice application logs to a centralized logging or SIEM platform and retain invitation-lifecycle events.
- Monitor administrative audit trails for unexpected role assignments following invitation redemption.
- Track outbound invitation email volume and downstream acceptance rates to baseline normal onboarding behavior.
How to Mitigate CVE-2026-61608
Immediate Actions Required
- Upgrade all SolidInvoice deployments to version 3.0.1 or later.
- Invalidate every outstanding UserInvitation issued by a vulnerable version and reissue where still needed.
- Audit recent company memberships to confirm each user joined through a legitimate, recent invitation.
Patch Information
SolidInvoice 3.0.1 introduces expiry handling for UserInvitation entities and rejects stale tokens. Release notes and source changes are published in the SolidInvoice Release v3.0.1 announcement. Administrators should apply the upgrade using the vendor's standard deployment procedure and validate that the invitation acceptance flow rejects tokens older than the configured expiry.
Workarounds
- If upgrading immediately is not possible, manually purge pending UserInvitation records from the database on a short rotation.
- Restrict invitation issuance to administrators and require out-of-band confirmation before granting elevated roles.
- Enforce mailbox security controls, including multi-factor authentication and short retention for onboarding messages, to reduce exposure of invitation links.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
