PT-2026-52633 · Unknown · Fossbilling

·

CVE-2026-43920

·

Published

2026-06-25

·

Updated

2026-06-26

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FOSSBilling versions 0.5.4 through 0.7.2
Description The /run-patcher endpoint is accessible without authentication, allowing remote users to trigger privileged maintenance operations. These operations include configuration migrations, database schema changes (such as ALTER TABLE, DROP TABLE, and UPDATE statements), filesystem mutations (deletions and renames), and cache clearing. The endpoint lacks administrator authentication, CSRF validation, and CLI context requirements. An attacker can trigger these routines via an HTTP GET request to the /run-patcher endpoint, which may lead to denial-of-service attacks, session invalidation, or an inconsistent database state due to repeated or concurrent requests.

Exploit

Fix

DoS

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43920
GHSA-PRX6-M547-RFMG

Affected Products

Fossbilling