CVE-2026-71626: Invoice Ninja vulnerability
Published Sep 4, 2026
·Updated
An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components
Affected Software
1 affected component
Invoice Ninja=5.13.24
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is described as remotely exploitable. The provided data does not state whether authentication, specific webhook permissions, or other prerequisites are required.
2
Which parts of the application are implicated?
The affected components identified are StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php. These names indicate the issue is associated with webhook creation, updating, and individual webhook handling.
3
What information could be exposed?
The issue may allow an attacker to obtain sensitive information. The provided data does not identify the specific information that could be accessed.