Executive brief
FOSSBilling, an open-source billing and client management platform, contains a security flaw where a maintenance tool used for system updates is accessible to anyone on the internet. An attacker can remotely trigger this tool to modify system settings, delete files, or reset database tables without needing a password. This can lead to a total service outage, loss of access for legitimate administrators and clients, and potential corruption of business data.
Technical details
A missing authentication check (CWE-306) exists in the 'checkUpdatePatcher()' function within 'src/load.php'. This function is invoked during early application initialization before authentication or CSRF middleware are applied. An unauthenticated remote attacker can trigger the '/run-patcher' endpoint via a simple HTTP GET request. This executes the 'UpdatePatcher' class, which performs privileged operations including database migrations (ALTER/DROP TABLE), configuration writes to 'config.php', and filesystem deletions. While a cache-based guard exists, it can be bypassed after version upgrades or cache clears, leading to denial-of-service or inconsistent database states. The issue is resolved in version 0.8.0.
Affected products
- FOSSBilling FOSSBilling 0.5.4 - 0.7.2
Timeline
- 2026-05-28: patched: Version 0.8.0 released
- 2026-06-12: advisory: GitHub Security Advisory published
- 2026-06-26: disclosed: CVE-2026-43920 published to NVD