---
id: CVE-2026-24913
title: SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier
summary: >-
  SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If
  this vulnerability is exploited, information stored in the database may be
  obtained or altered by a user who can log in to the product.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: icz
product: matcha_invoice
affected:
  - matcha_invoice <= 2.6.6
published: '2026-04-08'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-24913'
references:
  - url: 'https://jvn.jp/en/jp/JVN33581068/'
    label: vultures@jpcert.or.jp
  - url: 'https://oss.icz.co.jp/news/?p=1386'
    label: vultures@jpcert.or.jp
tags:
  - nvd
epss: 0.00301
epssPercentile: 0.2024
ingestedAt: '2026-07-25T23:05:58.751Z'
---

## Overview

SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.

## Affected

- `matcha_invoice <= 2.6.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
