CVE-2026-83743 | invoiceninja Invoice Ninja up to 5.13.26 Vendor Portal Profile Update /vedor/profile/ vendor_contact authorization

SecurityVulns

A vulnerability labeled as critical has been found in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the argument vendor_contact can lead to authorization bypass.

This vulnerability appears as CVE-2026-83743. The attack may be performed from remote. In addition, an exploit is available.

The affected component should be upgraded.VulDB Recent EntriesRead More