CVE-2026-61614CWE-598

CVE-2026-61614

Medium · published September 4, 2026

CVSS v3.1
5.9
EPSS
0%
Percentile
20.5
In the wild
Unconfirmed
What it is

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credentials to be recorded in server access logs, proxy logs, browser history, and HTTP Referer headers sent to third-party origins. Version 3.0.1 fixes the issue.

The record
Technical detail
CVSS v3.1
5.9 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00283 · 20.5th percentile
Weakness
CWE-598 · Use of HTTP Request With Sensitive Query String
Published
2026-09-04T22:17Z
References (2)
EPSS history
Timeline
  • 06 SEP 03:33Z
    EPSS moved — → 0%
    epss
  • 04 SEP 17:48Z
    SolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credentials in server logs and browser history
    cvelistv5