PT-2026-51521 · Unknown · Fossbilling
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
FOSSBilling versions 0.5.4 through 0.7.x
Description
An authorization bypass in the API role handling allows unauthenticated access to privileged '/api/system/*' endpoints. Because
system resolves to the cron admin identity, attackers can invoke admin API methods without a valid session, credentials, or CSRF token.Recommendations
Update to version 0.8.0.
Block external access to '/api/system/*' at the reverse proxy or Web Application Firewall (WAF).
Restrict API access to trusted source IPs using the
api.allowed ips setting.
Rotate all admin and client API tokens immediately.
Invalidate active sessions and reset high-privilege credentials.
Review API request logs for suspicious '/api/system/' access.Exploit
Fix
Missing Authentication
Incorrect Authorization
Missing Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fossbilling