CVE-2026-24913 is a SQL injection vulnerability affecting MATCHA INVOICE version 2.6.6 and earlier that allows authenticated users to query, obtain, or modify database information. The vulnerability carries a high CVSS score of 8.8, with a network attack vector, low complexity, and low privilege requirements, resulting in high impact across confidentiality, integrity, and availability. While the EPSS score indicates relatively low probability of exploitation in the wild at 0.000350000, the vulnerability has a moderate FAUCET risk score of 52.0 out of 100. The vulnerability is not currently tracked on the Known Exploited Vulnerabilities catalog and shows no signs of active exploitation or widespread community attention. Organizations running MATCHA INVOICE 2.6.6 or earlier should prioritize patching, as the attack requires only valid login credentials but poses significant data compromise risks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.6CPE matchmatch criteria | cpe:2.3:a:icz:matcha_invoice:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.