Home

Description

Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server.

PUBLISHED Reserved 2026-04-03 | Published 2026-04-08 | Updated 2026-04-08 | Assigner jpcert




MEDIUM: 4.7CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Problem types

Unrestricted upload of file with dangerous type

Product status

2.6.6 and earlier
affected

References

oss.icz.co.jp/news/?p=1386

jvn.jp/en/jp/JVN33581068/

cve.org (CVE-2026-33273)

nvd.nist.gov (CVE-2026-33273)

Download JSON