Skip to main content
Vulnerability Database/CVE-2026-61688

CVE-2026-61688: SolidInvoice Information Disclosure Flaw

CVE-2026-61688 is an information disclosure vulnerability in SolidInvoice allowing authenticated users to access other users' API request histories. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-61688 Overview

CVE-2026-61688 is an authorization flaw in SolidInvoice, an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company. The flaw stems from manipulating two writable Symfony UX LiveComponent props on the DataGrid component. The issue is classified under CWE-639 (Authorization Bypass Through User-Controlled Key). SolidInvoice version 3.0.1 fixes the vulnerability.

Critical Impact

Any authenticated tenant user can enumerate and read other users' API request histories, exposing sensitive API activity metadata and potentially embedded request/response data within the same company.

Affected Products

  • SolidInvoice open-source invoicing platform
  • All versions prior to 3.0.1
  • Deployments using the Symfony UX LiveComponent DataGrid component for API token history

Discovery Timeline

  • 2026-09-04 - CVE-2026-61688 published to the National Vulnerability Database (NVD)
  • 2026-09-10 - Last updated in NVD database

Technical Details for CVE-2026-61688

Vulnerability Analysis

SolidInvoice exposes an API token management interface backed by a Symfony UX LiveComponent DataGrid. LiveComponents synchronize state between the browser and server by round-tripping component props. Two of those props are writable and control the dataset being queried. An authenticated attacker can modify those props to reference API tokens owned by other users in the same company. The server then returns the associated API request history without verifying that the requester owns the referenced token.

The flaw is an insecure direct object reference (IDOR) at the LiveComponent layer. Authentication is enforced, but object-level authorization is missing.

Root Cause

The root cause is a missing authorization check on user-controlled input, mapped to [CWE-639]. The DataGrid component trusts the writable props submitted from the client and uses them to scope database queries. Because tenant boundaries within the company are not enforced on those specific props, any user in the tenant can pivot the query to another user's token history.

Attack Vector

Exploitation requires only a valid low-privilege account within the target company. The attacker interacts with the SolidInvoice web UI, intercepts the LiveComponent update request, and rewrites the two writable props to target another user's token identifier. The server responds with the victim's API request history. No user interaction from the victim is required, and no elevated privileges are needed. Refer to the GitHub Security Advisory GHSA-jhv9-9fv9-67cr for advisory details.

Detection Methods for CVE-2026-61688

Indicators of Compromise

  • LiveComponent update requests to the API token DataGrid endpoint where the token or owner prop differs from the authenticated session user.
  • Repeated DataGrid requests from a single session enumerating sequential token identifiers.
  • Access log entries showing one user retrieving API history records associated with another user's token IDs.

Detection Strategies

  • Instrument the SolidInvoice application layer to log the authenticated user, the requested token owner, and the resolved company scope on every DataGrid request.
  • Alert when the requesting user does not match the owner of the token referenced in the LiveComponent props.
  • Baseline normal per-user API token history read patterns and flag statistical outliers.

Monitoring Recommendations

  • Forward SolidInvoice web and application logs to a centralized analytics pipeline for correlation across sessions.
  • Monitor for LiveComponent prop tampering by comparing server-rendered prop values against client-submitted values.
  • Review audit trails for API token management pages after upgrading to confirm no historical abuse occurred.

How to Mitigate CVE-2026-61688

Immediate Actions Required

  • Upgrade SolidInvoice to version 3.0.1 or later without delay.
  • Rotate all API tokens issued prior to the upgrade to invalidate any credentials whose history may have been exposed.
  • Review recent access logs for signs of cross-user DataGrid queries and notify affected users if abuse is suspected.

Patch Information

The fix is included in the SolidInvoice 3.0.1 release. The maintainers added authorization enforcement so that the DataGrid component only returns API request history owned by the authenticated user. Details are documented in GitHub Security Advisory GHSA-jhv9-9fv9-67cr.

Workarounds

  • If immediate upgrade is not possible, restrict access to the API token management interface to trusted administrators only.
  • Place SolidInvoice behind a reverse proxy that inspects LiveComponent requests and rejects tampered props referencing tokens outside the session user's scope.
  • Temporarily disable API token issuance to limit the volume of history data exposed until the patch is applied.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.