CVE-2026-58450: Invoice Ninja 5.13.26 - Open Redirect in Client Portal Login via intended Parameter

Published Jun 30, 2026
·
Updated

Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthenticated attackers to redirect authenticated victims to attacker-controlled external URLs by injecting a malicious value into the intended query parameter. Attackers can craft a client login link with an external URL in the intended parameter, which is stored in the session without host validation and emitted verbatim via a bare redirect in the ContactLoginController authenticated() handler after the victim completes a legitimate login, enabling phishing attacks.

Affected Software

1 affected component
Invoice Ninja Invoice Ninja<=5.13.26

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Invoice Ninja to a version that resolves this vulnerability.

    Fixed in 5.13.26
  2. Compensating control

    Mitigate the phishing risk caused by an open redirect in the Invoice Ninja client portal login by preventing redirects based on an unvalidated external value in the intended query parameter (i.e., add host/target validation so authenticated redirects cannot send users to attacker-controlled external URLs).

Event History

Jun 30, 2026
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Jan 20, 58467
Event
via NVD·05:51 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-58450?

The severity of CVE-2026-58450 is rated as medium with a score of 4.3.

2

How do I fix CVE-2026-58450?

To mitigate CVE-2026-58450, validate and sanitize the 'intended' parameter in the client portal login to prevent open redirects.

3

What are the potential impacts of CVE-2026-58450?

The potential impacts of CVE-2026-58450 include the possibility for attackers to redirect users to malicious external sites.

4

Who is affected by CVE-2026-58450?

Any user of Invoice Ninja version 5.13.26 and below is potentially affected by CVE-2026-58450.

5

Is CVE-2026-58450 a zero-day vulnerability?

CVE-2026-58450 is not categorized as a zero-day since it was published on June 30, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203