Junglewise Threat Intelligence

CVE-2026-71626: Invoice Ninja information disclosure via webhook components

CVE-2026-71626 · Severity: high · CVSS 7.5 · Published 2026-09-04

Executive brief

Invoice Ninja is a web-based invoicing and accounting platform used by businesses to manage billing operations. A vulnerability in versions up to 5.13.24 allows a remote attacker to access sensitive information through webhook-related API endpoints, potentially exposing customer data, financial records, or API credentials without authentication.

Technical details

The vulnerability exists in the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components of Invoice Ninja. It is classified as an information disclosure issue (CWE-200) that permits unauthenticated remote access to sensitive data via the webhook API endpoints. The attack requires only network connectivity to the affected Invoice Ninja instance; no prior authentication or user interaction is needed. An attacker can exploit this to retrieve confidential information such as webhook configurations, API keys, or related sensitive data. Patches are available in versions later than 5.13.24.

Affected products

  • Invoice Ninja Invoice Ninja up to 5.13.24

Timeline

  • 2026-09-04: disclosed

References

Related threats