PT-2026-44504 · Unknown · Fossbilling

·

CVE-2026-43918

·

Published

2026-05-26

·

Updated

2026-07-08

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FOSSBilling versions prior to 0.8.0
Description Authenticated sessions for client, staff, or admin accounts are not invalidated when the account is suspended or marked inactive. The session identity loaders in src/di.php (loggedin client and loggedin admin) only reject sessions if the account record is completely removed from the database, failing to verify if the account status is active. This allows deactivated users to maintain full access until the session expires naturally.
Recommendations Update to version 0.8.0.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43918
GHSA-QV6C-V49W-8G2J

Affected Products

Fossbilling