Skip to main content
Vulnerability Database/CVE-2026-61608

CVE-2026-61608: SolidInvoice Auth Bypass Vulnerability

CVE-2026-61608 is an authentication bypass flaw in SolidInvoice where invitation links never expire, allowing unauthorized access at any time. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-61608 Overview

CVE-2026-61608 is an insufficient session expiration vulnerability in SolidInvoice, an open-source invoicing platform. Versions prior to 3.0.1 create UserInvitation entities without an expiry timestamp. Invitation links emailed to users therefore remain valid indefinitely. An attacker who obtains a leaked, forwarded, or archived invitation email can redeem the link at any point in the future to join a target company or silently attach a compromised email account to that company. The vulnerability is tracked under [CWE-613: Insufficient Session Expiration]. SolidInvoice 3.0.1 addresses the flaw.

Critical Impact

Attackers with access to old invitation emails can join a SolidInvoice company account long after the invitation was issued, gaining unauthorized access to invoicing data.

Affected Products

  • SolidInvoice versions prior to 3.0.1
  • SolidInvoice UserInvitation entity workflow
  • Deployments relying on emailed invitation links for user onboarding

Discovery Timeline

  • 2026-09-04 - CVE-2026-61608 published to NVD
  • 2026-09-10 - Last updated in NVD database

Technical Details for CVE-2026-61608

Vulnerability Analysis

SolidInvoice issues invitation tokens to onboard new users into a company workspace. Prior to version 3.0.1, the UserInvitation entity omits any expiration field. The application accepts an invitation token as valid whenever it is presented, regardless of how much time has elapsed since issuance.

This breaks a core assumption of email-based onboarding flows: that invitation links are short-lived, single-purpose credentials. Because the token has no bounded lifetime, its exposure surface expands to every mail archive, backup, forwarding rule, and downstream mailbox that ever received the message.

Exploitation requires the attacker to obtain the invitation email and to convince a user (or themselves) to click the link, which is why the CVSS vector notes user interaction and higher attack complexity. Successful redemption grants membership in the target company with the role encoded in the invitation.

Root Cause

The root cause is a missing temporal control on authentication artifacts, classified as [CWE-613]. The UserInvitation schema does not persist an expiresAt timestamp, and the redemption code path performs no time-based validation. Any policy that assumes an invitation link is only usable for a limited window is silently violated.

Attack Vector

The attack is remote and network-based. An adversary needs read access to a historical invitation email through a compromised mailbox, mail server backup, unencrypted archive, or a misdirected forward. The attacker then submits the invitation token to the SolidInvoice instance through the normal acceptance workflow. If the invitation was issued to an address the attacker now controls, they can bind that address to the company without further interaction from administrators.

Refer to the GitHub Security Advisory GHSA-5gcp-fm29-jgrp for vendor-authored technical details.

Detection Methods for CVE-2026-61608

Indicators of Compromise

  • Successful acceptance of UserInvitation records whose creation timestamp is weeks or months old.
  • New company memberships bound to email addresses that were previously deactivated or reassigned.
  • Redemption of invitation tokens from IP addresses or user agents that do not match the original invitee.

Detection Strategies

  • Query the SolidInvoice database for UserInvitation rows joined against acceptance events and flag deltas above an acceptable onboarding window, for example greater than 7 days.
  • Correlate invitation-accepted events with recent mailbox compromise indicators for the invitee address.
  • Alert on repeated invitation acceptances tied to the same company from disparate geographies.

Monitoring Recommendations

  • Ship SolidInvoice application logs to a centralized logging or SIEM platform and retain invitation-lifecycle events.
  • Monitor administrative audit trails for unexpected role assignments following invitation redemption.
  • Track outbound invitation email volume and downstream acceptance rates to baseline normal onboarding behavior.

How to Mitigate CVE-2026-61608

Immediate Actions Required

  • Upgrade all SolidInvoice deployments to version 3.0.1 or later.
  • Invalidate every outstanding UserInvitation issued by a vulnerable version and reissue where still needed.
  • Audit recent company memberships to confirm each user joined through a legitimate, recent invitation.

Patch Information

SolidInvoice 3.0.1 introduces expiry handling for UserInvitation entities and rejects stale tokens. Release notes and source changes are published in the SolidInvoice Release v3.0.1 announcement. Administrators should apply the upgrade using the vendor's standard deployment procedure and validate that the invitation acceptance flow rejects tokens older than the configured expiry.

Workarounds

  • If upgrading immediately is not possible, manually purge pending UserInvitation records from the database on a short rotation.
  • Restrict invitation issuance to administrators and require out-of-band confirmation before granting elevated roles.
  • Enforce mailbox security controls, including multi-factor authentication and short retention for onboarding messages, to reduce exposure of invitation links.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.