Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Solidinvoice
Solidinvoice solidinvoice |
|
| Vendors & Products |
Solidinvoice
Solidinvoice solidinvoice |
Fri, 04 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning a leaked, forwarded, or archived invitation email can be used at any time in the future to join a company or silently add a compromised email account to a company. Version 3.0.1 fixes the issue. | |
| Title | SolidInvoice's user invitation tokens have no expiry, allowing indefinite unauthorized company access via leaked or old invitation links | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-04T18:17:56.833Z
Reserved: 2026-07-10T17:36:04.597Z
Link: CVE-2026-61608
No data.
Status : Received
Published: 2026-09-04T18:17:55.147
Modified: 2026-09-04T19:17:25.413
Link: CVE-2026-61608
No data.
OpenCVE Enrichment
Updated: 2026-09-04T21:30:07Z