PT-2026-56042 · Unknown · Fossbilling

·

CVE-2026-53647

·

Published

2026-07-06

·

Updated

2026-07-07

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FOSSBilling versions 0.5.3 through 0.7.2
Description The Guest serviceapikey/get info API endpoint is accessible without authentication. An attacker with a valid API key can retrieve all custom configuration parameters, specifically the custom * fields, stored in the database record associated with that key. These fields are managed by administrators and may contain sensitive business information, including pricing tiers, feature flags, rate limits, expiry overrides, or access scope data.
Recommendations Update to version 0.8.0. Avoid storing sensitive data in custom * API key configuration fields. Monitor API logs for suspicious calls to the /api/guest/serviceapikey/get info endpoint. Disable the Serviceapikey module if it is not in active use.

Exploit

Fix

Information Disclosure

Missing Authorization

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53647
GHSA-737Q-9GPR-6MPQ

Affected Products

Fossbilling