PT-2026-51521 · Unknown · Fossbilling

·

CVE-2026-27604

·

Published

2026-06-23

·

Updated

2026-06-24

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions FOSSBilling versions 0.5.4 through 0.7.x
Description An authorization bypass in the API role handling allows unauthenticated access to privileged '/api/system/*' endpoints. Because system resolves to the cron admin identity, attackers can invoke admin API methods without a valid session, credentials, or CSRF token.
Recommendations Update to version 0.8.0. Block external access to '/api/system/*' at the reverse proxy or Web Application Firewall (WAF). Restrict API access to trusted source IPs using the api.allowed ips setting. Rotate all admin and client API tokens immediately. Invalidate active sessions and reset high-privilege credentials. Review API request logs for suspicious '/api/system/' access.

Exploit

Fix

Missing Authentication

Incorrect Authorization

Missing Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27604
GHSA-57MV-JM88-66JC
GHSA-78X5-C8GW-8279

Affected Products

Fossbilling