CVE-2026-83743
invoiceninja Invoice Ninja Vendor Portal Profile Update profile authorization
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the argument vendor_contact can lead to authorization bypass. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 5.13.27 is able to mitigate this issue. This patch is called f86fd9697ce7bd0d28adbe2e6c5890780482ea90. The affected component should be upgraded.
| CWE | CWE-639 CWE-285 |
| Vendor | invoiceninja |
| Product | invoice ninja |
| Published | Sep 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for invoiceninja invoice ninja
Be the first to know when new medium vulnerabilities affecting invoiceninja invoice ninja are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
invoiceninja / Invoice Ninja
5.13.0 5.13.1 5.13.2 5.13.3 5.13.4 5.13.5 5.13.6 5.13.7 5.13.8 5.13.9 5.13.10 5.13.11 5.13.12 5.13.13 5.13.14 5.13.15 5.13.16 5.13.17 5.13.18 5.13.19 5.13.20 5.13.21 5.13.22 5.13.23 5.13.24 5.13.25 5.13.26
References
vuldb.com: https://vuldb.com/vuln/397499 vuldb.com: https://vuldb.com/vuln/397499/cti vuldb.com: https://vuldb.com/cve/CVE-2026-83743 vuldb.com: https://vuldb.com/submit/880053 ashutosh-jena.in: https://ashutosh-jena.in/blog/broken-access-control-idor-in-invoice-ninja-vendor-portal-v51326 github.com: https://github.com/invoiceninja/invoiceninja/commit/f86fd9697ce7bd0d28adbe2e6c5890780482ea90 github.com: https://github.com/invoiceninja/invoiceninja/releases/tag/v5.13.27
Credits
๐ MAVERICK-VF142 (VulDB User)