Junglewise Threat Intelligence

CVE-2026-9409: Sushmi-pal Invoice-System privilege escalation in User Management Handler

CVE-2026-9409 · Severity: medium · CVSS 4.3 · Published 2026-05-25

Executive brief

A security flaw in the Sushmi-pal Invoice-System allows users to change their own account permissions. By manipulating the 'role' parameter during account creation or updates, a regular user can grant themselves administrative access. This could lead to unauthorized access to sensitive financial data and full control over the invoicing platform.

Technical details

An improper authorization vulnerability (CWE-285/CWE-266) exists in the User Management Handler of the Sushmi-pal Invoice-System. The '/user' endpoint (POST/PUT methods) fails to implement server-side middleware to restrict role assignments to administrators. An authenticated attacker can manipulate the 'role' parameter in a request to elevate their privileges to 'admin'. This is likely due to insecure mass assignment or lack of Laravel Policy enforcement. A public exploit (PoC) is available, and the vendor has not yet released a patch for this rolling release.

Affected products

  • Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b

Timeline

  • 2026-04-26: disclosed: Initial discovery and PoC published on GitHub Gist.
  • 2026-05-25: advisory: CVE-2026-9409 published.

References

Related threats