PT-2026-56036 · Unknown · Fossbilling

·

CVE-2026-53643

·

Published

2026-07-06

·

Updated

2026-07-07

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FOSSBilling versions prior to 0.8.0
Description Low-privileged staff accounts can perform unauthorized actions through admin API endpoints. This issue stems from the can always access module flag, which grants all staff access to specific modules, combined with unsafe parameter handling or insufficient permission checks on individual endpoints.
Recommendations Update to version 0.8.0. Restrict staff accounts to only those who require access to sensitive settings. Use a reverse proxy or WAF to restrict access to the affected admin API endpoints to trusted IP addresses or higher-privilege roles.

Exploit

Fix

Information Disclosure

Missing Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53643
GHSA-563Q-G4R4-6F9M

Affected Products

Fossbilling