PT-2026-56031 · Unknown · Fossbilling

·

CVE-2026-43927

·

Published

2026-07-06

·

Updated

2026-07-07

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FOSSBilling versions prior to 0.8.0
Description A race condition in the cart checkout flow allows an authenticated client to apply a promo code more times than its configured maximum limit. By sending concurrent checkout requests before the system can increment the usage count for any single request, a client can obtain unlimited discounted or free orders using a single-use or limited-use promo code.
Recommendations Update to version 0.8.0. Disable promo codes entirely until a patch is available. Monitor the promo table for used values exceeding maxuses and manually review affected orders.

Exploit

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43927
GHSA-W898-CX35-25GH

Affected Products

Fossbilling