CVE-2026-83743: invoiceninja Invoice Ninja Vendor Portal Profile Update profile authorization
A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the argument vendorcontact can lead to authorization bypass. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 5.13.27 is able to mitigate this issue. This patch is called f86fd9697ce7bd0d28adbe2e6c5890780482ea90. The affected component should be upgraded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
invoiceninja Invoice Ninja Vendor Portal Profile Update profile authorizationto a version that resolves this vulnerability.Fixed in 5.13.27Patch f86fd9697ce7bd0d28adbe2e6c5890780482ea90
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs at least low-level privileges and remote access to the Invoice Ninja Vendor Portal Profile Update functionality. No user interaction is required.
Are default deployments affected?
The available information identifies Invoice Ninja versions up to 5.13.26 as affected, but does not state whether the vulnerable Vendor Portal Profile Update component is enabled or reachable in a default deployment.
What should be done to remediate the issue?
Upgrade Invoice Ninja to version 5.13.27. The mitigation is associated with patch f86fd9697ce7bd0d28adbe2e6c5890780482ea90.
Is public exploitation information available?
Yes. A public exploit has been made available and could be used in attacks.