PT-2026-56009 · Unknown · Fossbilling

·

CVE-2026-42331

·

Published

2026-07-06

·

Updated

2026-07-06

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions FOSSBilling versions prior to 0.8.0
Description The Guest API 'invoice/update' endpoint lacks an authorization check. This allows an unauthenticated user who possesses an invoice hash to modify the payment gateway of an unpaid invoice by changing the gateway id variable to any payment gateway already configured in the system. Invoice hashes may be exposed through email links, referrer headers, or shared URLs. The impact is limited by the invoice accessible from hash system setting and the requirement that the gateway must be pre-installed by an administrator.
Recommendations Update to version 0.8.0.

Exploit

Fix

Missing Authentication

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42331
GHSA-8755-W77F-3G7J

Affected Products

Fossbilling