PT-2026-52076 · Unknown · Fossbilling
CVE-2026-27708
·
Published
2026-06-24
·
Updated
2026-06-25
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FOSSBilling versions prior to 0.8.0
Description
The Servicecustom Client API's
call() method accepts an order id parameter and retrieves the associated order without verifying if the authenticated client owns it. This allows an authenticated client to access custom services of other clients by guessing sequential order IDs through an Insecure Direct Object Reference (IDOR), which is a flaw where an application provides direct access to objects based on user-supplied input. This can result in a confidentiality breach, exposing personally identifiable information (PII) such as name, email, phone, address, company details, and VAT number, as well as service configuration data.Recommendations
Update to version 0.8.0.
Exploit
Fix
Improper Access Control
Missing Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fossbilling