---
id: CVE-2026-33273
title: >-
  Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE
  2.6.6 and earlier
summary: >-
  Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE
  2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may
  be created by an administrator of the product. As a result, arbitrary code may
  be…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: icz
product: matcha_invoice
affected:
  - matcha_invoice <= 2.6.6
published: '2026-04-08'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33273'
references:
  - url: 'https://jvn.jp/en/jp/JVN33581068/'
    label: vultures@jpcert.or.jp
  - url: 'https://oss.icz.co.jp/news/?p=1386'
    label: vultures@jpcert.or.jp
tags:
  - nvd
epss: 0.00407
epssPercentile: 0.32145
ingestedAt: '2026-07-25T23:05:58.802Z'
---

## Overview

Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server.

## Affected

- `matcha_invoice <= 2.6.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
