PT-2026-56043 · Unknown · Fossbilling

·

CVE-2026-53648

·

Published

2026-07-06

·

Updated

2026-07-07

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FOSSBilling versions prior to 0.8.1
Description Downloadable product files are stored using a deterministic path derived from the filename. When an administrator uploads a file, the system stores it as md5(<original filename>) within the uploads directory. Since the path depends solely on the client-supplied filename, multiple products or order files uploaded with the same original filename will resolve to the same storage path. Consequently, a subsequent upload can overwrite a previous one, leading customers or administrators to download the incorrect file.
Recommendations Update to version 0.8.1. Restrict the servicedownloadable.manage permission to fully trusted administrators only. Ensure downloadable product files use unique filenames before upload to reduce accidental collisions.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53648
GHSA-X7P2-XHVC-CFP9

Affected Products

Fossbilling