PT-2026-52090 · Unknown · Fossbilling
CVE-2026-33543
·
Published
2026-06-24
·
Updated
2026-06-25
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FOSSBilling versions prior to 0.8.0
Description
FOSSBilling exposes a guest API endpoint '/api/guest/staff/create' designed for initial administrator bootstrap. A flawed guard check using the
is countable() function on a value that returns a Model Admin object or null causes the check to always evaluate as true. This allows an attacker to bypass the admin-existence check and create a new administrator account, granting them a fully privileged admin session even if an administrator already exists.Recommendations
Update to version 0.8.0.
As a temporary workaround, restrict access to the '/api/guest/staff/create' API endpoint.
Exploit
Fix
Authentication Bypass Using an Alternate Path or Channel
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fossbilling