PT-2026-56033 · Unknown · Fossbilling

·

CVE-2026-53640

·

Published

2026-07-06

·

Updated

2026-07-07

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FOSSBilling versions prior to 0.8.0
Description Low-privileged staff accounts can read sensitive data through admin API endpoints that lack proper permission checks. Although write endpoints enforce fine-grained permissions, the corresponding read endpoints do not have authorization guards.
Recommendations Update to version 0.8.0. Restrict staff accounts to only those who require access to sensitive data. Use a reverse proxy or WAF to restrict access to the affected admin API endpoints.

Exploit

Fix

Information Disclosure

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53640
GHSA-JQW4-3HJ3-8M4F

Affected Products

Fossbilling