Skip to main content
Vulnerability Database/CVE-2026-61614

CVE-2026-61614: SolidInvoice API Token Exposure Vulnerability

CVE-2026-61614 is an information disclosure vulnerability in SolidInvoice that exposes API tokens through URL parameters, logging them in server access logs and browser history. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-61614 Overview

SolidInvoice, an open-source invoicing platform, contains an information exposure vulnerability in its REST API authenticator. Prior to version 3.0.1, the authenticator accepts bearer tokens through a ?token= URL query parameter as a fallback to the X-API-TOKEN header. This design causes long-lived API credentials to be recorded in server access logs, proxy logs, browser history, and HTTP Referer headers transmitted to third-party origins. An attacker with access to any of these logging surfaces can harvest valid API tokens and impersonate legitimate users against the SolidInvoice API. The vulnerability is tracked under [CWE-598: Use of GET Request Method With Sensitive Query Strings]. Version 3.0.1 removes the query parameter fallback.

Critical Impact

Bearer tokens transmitted via URL query strings can leak into logs and Referer headers, enabling credential theft and unauthorized API access.

Affected Products

  • SolidInvoice open-source invoicing platform
  • All versions prior to 3.0.1
  • Deployments exposing the REST API to reverse proxies or browsers

Discovery Timeline

  • 2026-09-04 - CVE-2026-61614 published to NVD
  • 2026-09-10 - Last updated in NVD database

Technical Details for CVE-2026-61614

Vulnerability Analysis

The SolidInvoice REST API authenticator supports two mechanisms for supplying bearer tokens. The primary mechanism is the X-API-TOKEN HTTP header, which keeps the credential inside the request headers. The fallback mechanism accepts the same token through a ?token= URL query parameter. Query parameters travel as part of the request URI and are persisted by many components along the request path.

When clients or integrations use the query parameter form, the token is captured in web server access logs, upstream reverse proxy logs, CDN telemetry, and browser history. Outbound navigation from an authenticated page also leaks the URI, including the token, in the HTTP Referer header sent to third-party origins. Because SolidInvoice API tokens are long-lived, a single exposure grants persistent access until the token is rotated.

Root Cause

The root cause is the acceptance of sensitive authentication material inside a GET request URI. This pattern conflicts with guidance that credentials must be transmitted only in request bodies or headers protected from logging. Refer to the GitHub Security Advisory GHSA-mp4c-675j-mv67 for the maintainer analysis.

Attack Vector

An attacker does not need to interact with the SolidInvoice server directly. Any actor with read access to web server logs, proxy logs, SIEM archives, browser history, or referrer analytics on third-party sites can extract tokens. Once obtained, the attacker replays the token against the SolidInvoice REST API to read or modify invoicing data. Exploitation is passive and leaves minimal forensic evidence beyond normal API activity.

Detection Methods for CVE-2026-61614

Indicators of Compromise

  • Access log entries containing ?token= or &token= parameters against SolidInvoice API endpoints
  • API requests originating from IP addresses outside expected integration ranges
  • Referer headers in outbound traffic that include SolidInvoice URIs with token parameters
  • Unexpected API activity outside of scheduled integration windows

Detection Strategies

  • Grep historical web server, load balancer, and WAF logs for the token= query parameter targeting SolidInvoice hostnames
  • Correlate authenticated API activity with source IPs and user agents to identify anomalous token reuse
  • Review browser telemetry and endpoint DLP tooling for URLs containing embedded API tokens

Monitoring Recommendations

  • Enable alerting on any request to SolidInvoice endpoints containing credential-like query parameters
  • Rotate SolidInvoice API tokens on a defined schedule and monitor token issuance events
  • Audit third-party analytics and error-reporting integrations that may capture full request URLs

How to Mitigate CVE-2026-61614

Immediate Actions Required

  • Upgrade SolidInvoice to version 3.0.1 or later without delay
  • Invalidate and reissue all existing API tokens after upgrading
  • Purge or restrict access to historical logs that may contain leaked tokens
  • Notify integration owners to switch clients to the X-API-TOKEN header exclusively

Patch Information

SolidInvoice version 3.0.1 removes the ?token= query parameter fallback and requires bearer tokens to be supplied via the X-API-TOKEN header. Download the release from the SolidInvoice 3.0.1 release notes.

Workarounds

  • Configure the reverse proxy or WAF to reject requests containing a token query parameter
  • Strip query strings from access log formats until the upgrade is completed
  • Enforce Referrer-Policy: no-referrer on SolidInvoice responses to reduce Referer leakage
bash
# Example nginx rule to block token query parameter until patched
if ($arg_token) {
    return 400;
}
add_header Referrer-Policy "no-referrer" always;

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.