PT-2026-56010 · Unknown · Fossbilling

·

CVE-2026-42341

·

Published

2026-07-06

·

Updated

2026-07-07

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions FOSSBilling versions 0.6.0 through 0.7.2
Description An unauthenticated payment bypass exists in the IPN callback endpoint /ipn.php. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment by sending a single crafted HTTP request.
Recommendations Update to version 0.8.0. Disable the Custom payment gateway if not actively needed. Restrict access to the /ipn.php endpoint at the web server level using IP allowlisting.

Exploit

Fix

Origin Validation Error

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42341
GHSA-5493-9M76-2QRR

Affected Products

Fossbilling