Junglewise Threat Intelligence

CVE-2026-42341: FOSSBilling unauthenticated payment bypass in IPN callback

CVE-2026-42341 · Severity: info · CVSS 9.2 · Published 2026-07-06

Technologies: FOSSBilling. Vendors: FOSSBilling.

Executive brief

FOSSBilling is an open-source platform used by businesses to manage client billing, invoices, and automated service provisioning. A security flaw allows unauthorized individuals to bypass the payment process by sending a specially crafted web request to the system. This enables attackers to mark unpaid invoices as paid and credit their accounts with funds without actually spending money, potentially leading to the unauthorized activation of services like web hosting or software licenses.

Technical details

An unauthenticated payment bypass exists in FOSSBilling's Instant Payment Notification (IPN) callback endpoint (`ipn.php`). The vulnerability is caused by three primary failures: the `ipn.php` script hardcodes a flag to skip validation of invoice IDs, the processing logic bypasses the standard `isIpnValid()` security checks, and the 'Custom' payment adapter lacks any source or signature verification. An attacker can exploit this by sending a crafted HTTP request to the IPN endpoint to credit client accounts or activate orders. Because invoice IDs are sequential, an attacker could potentially automate the exploitation of multiple invoices. The issue is resolved in version 0.8.0.

Affected products

  • FOSSBilling FOSSBilling >= 0.6.0, <= 0.7.2

Timeline

  • 2026-06-20: advisory: GitHub Security Advisory published
  • 2026-07-06: disclosed: NVD publication date
  • 2026-08-01: patched: Fixed in version 0.8.0

References

Related threats