CVE-2026-85290

MEDIUM CVSS 3.1: 5.3 EPSS 0.24%
Updated Sep 29, 2026
Invoiceplane
Parameter Value
CVSS 5.3 (MEDIUM)
Fixed In 1.7.2
Type CWE-117
Vendor Invoiceplane
Public PoC No

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from the URL path directly to the application log without neutralizing CRLF characters. An unauthenticated requester can place forged log lines into the audit trail by supplying a crafted cron_key value.

The injected entries can corrupt forensic records and interfere with log-based monitoring. This issue is fixed in version 1.7.2.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

invoiceplane:invoiceplane