CVE-2026-83743
Received Received - Intake

Authorization Bypass in Invoice Ninja Vendor Portal

Vulnerability report for CVE-2026-83743, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: VulDB

Description

A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the argument vendor_contact can lead to authorization bypass. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 5.13.27 is able to mitigate this issue. This patch is called f86fd9697ce7bd0d28adbe2e6c5890780482ea90. The affected component should be upgraded.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
invoiceninja invoice_ninja to 5.13.26 (inc)
invoiceninja invoice_ninja 5.13.27

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-83743 is a Broken Access Control vulnerability in Invoice Ninja Vendor Portal version 5.13.26. It allows an authenticated vendor to access and modify another vendor's profile by manipulating the vendor_contact identifier in the URL. This occurs due to insufficient authorization checks during route model binding, enabling unauthorized access to arbitrary vendor contact records.

Detection Guidance

Check Invoice Ninja version with: composer show invoiceninja/invoice-ninja. If version is below 5.13.27, the system is vulnerable. Inspect vendor portal URLs for vendor_contact parameter manipulation attempts in request logs.

Impact Analysis

An attacker could change sensitive details like email addresses, leading to full account takeover through password reset processes. This could result in reading or modifying another vendor's data, hijacking accounts, disrupting communications, or tampering with business records.

Compliance Impact

This vulnerability allows unauthorized access to and modification of vendor profile data, which could expose sensitive personal or business information. For GDPR, this may lead to unauthorized processing of personal data, potential data breaches, and failure to implement adequate security measures under Article 32. For HIPAA, it could result in unauthorized access to protected health information if vendor profiles contain such data, violating the Security Rule's requirements for access controls and integrity.

Mitigation Strategies

Upgrade Invoice Ninja to version 5.13.27 or later immediately. Apply the patch commit f86fd9697ce7bd0d28adbe2e6c5890780482ea90 if upgrading is not immediately possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-83743. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart