SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-71626

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Invoice Ninja v5.13.24 contains a vulnerability that enables remote attackers to access sensitive information through the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components. Organizations using this version of Invoice Ninja should prioritize patching to mitigate the risk of data exposure. Immediate action is recommended for those handling sensitive financial or personal data.

CVE
CVE-2026-71626
Severity
HIGH
CVSS
7.5
EPSS
0.32%

Original NVD Description

An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components