Medium severity6.8NVD Advisory· Published Sep 4, 2026· Updated Sep 4, 2026
CVE-2026-61608
CVE-2026-61608
Description
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, UserInvitation entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning a leaked, forwarded, or archived invitation email can be used at any time in the future to join a company or silently add a compromised email account to a company. Version 3.0.1 fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.0.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.