PT-2026-52076 · Unknown · Fossbilling

CVE-2026-27708

·

Published

2026-06-24

·

Updated

2026-06-25

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FOSSBilling versions prior to 0.8.0
Description The Servicecustom Client API's call() method accepts an order id parameter and retrieves the associated order without verifying if the authenticated client owns it. This allows an authenticated client to access custom services of other clients by guessing sequential order IDs through an Insecure Direct Object Reference (IDOR), which is a flaw where an application provides direct access to objects based on user-supplied input. This can result in a confidentiality breach, exposing personally identifiable information (PII) such as name, email, phone, address, company details, and VAT number, as well as service configuration data.
Recommendations Update to version 0.8.0.

Exploit

Fix

Improper Access Control

Missing Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27708
GHSA-P36W-9X66-488J

Affected Products

Fossbilling