Junglewise Threat Intelligence

CVE-2026-27604: FOSSBilling authorization bypass in system API endpoints

CVE-2026-27604 · Severity: info · CVSS 10 · Published 2026-06-23

Technologies: FOSSBilling. Vendors: FOSSBilling.

Executive brief

FOSSBilling is an open-source platform used by hosting providers to manage client billing and service provisioning. A security flaw allows anyone on the internet to bypass login requirements and access administrative functions without a password. An attacker could use this to steal customer data, modify billing records, or take full control of the server, potentially leading to a total service outage and data breach.

Technical details

An authorization bypass exists in the API role handling logic within FOSSBilling. The root cause is a logic error where an exception for disallowed roles is instantiated but never thrown, allowing the 'system' role to proceed. Because the 'system' role resolves to the 'cron admin' identity, unauthenticated attackers can invoke administrative API methods under `/api/system/*` without valid credentials, sessions, or CSRF tokens. This can be further chained with a Server-Side Template Injection (SSTI) vulnerability in the Twig rendering engine to achieve unauthenticated Remote Code Execution (RCE). The issue is patched in version 0.8.0.

Affected products

  • FOSSBilling FOSSBilling >= 0.5.4, < 0.8.0

Timeline

  • 2026-06-20: advisory: Initial GitHub security advisory published
  • 2026-05-28: patched: Version 0.8.0 released with fixes
  • 2026-06-23: disclosed: NVD publication and public blog disclosure

References