CVE-2026-33273

Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server.
References
Link Resource
https://jvn.jp/en/jp/JVN33581068/ Third Party Advisory
https://oss.icz.co.jp/news/?p=1386 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:icz:matcha_invoice:*:*:*:*:*:*:*:*

History

17 Apr 2026, 20:49

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.7
v2 : unknown
v3 : 7.2
First Time Icz
Icz matcha Invoice
CPE cpe:2.3:a:icz:matcha_invoice:*:*:*:*:*:*:*:*
References () https://jvn.jp/en/jp/JVN33581068/ - () https://jvn.jp/en/jp/JVN33581068/ - Third Party Advisory
References () https://oss.icz.co.jp/news/?p=1386 - () https://oss.icz.co.jp/news/?p=1386 - Vendor Advisory

08 Apr 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 06:16

Updated : 2026-04-17 20:49


NVD link : CVE-2026-33273

Mitre link : CVE-2026-33273

CVE.ORG link : CVE-2026-33273


JSON object : View

Products Affected

icz

  • matcha_invoice
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type