PT-2026-52090 · Unknown · Fossbilling

CVE-2026-33543

·

Published

2026-06-24

·

Updated

2026-06-25

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FOSSBilling versions prior to 0.8.0
Description FOSSBilling exposes a guest API endpoint '/api/guest/staff/create' designed for initial administrator bootstrap. A flawed guard check using the is countable() function on a value that returns a Model Admin object or null causes the check to always evaluate as true. This allows an attacker to bypass the admin-existence check and create a new administrator account, granting them a fully privileged admin session even if an administrator already exists.
Recommendations Update to version 0.8.0. As a temporary workaround, restrict access to the '/api/guest/staff/create' API endpoint.

Exploit

Fix

Authentication Bypass Using an Alternate Path or Channel

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33543
GHSA-28MH-J262-Q49W

Affected Products

Fossbilling