Junglewise Threat Intelligence

CVE-2026-43926: FOSSBilling missing rate limiting in password reset and auth endpoints

CVE-2026-43926 · Severity: info · CVSS 6.3 · Published 2026-06-04

Technologies: FOSSBilling. Vendors: FOSSBilling.

Executive brief

FOSSBilling is an open-source billing and client management platform. A security flaw in the password reset system allows attackers to repeatedly guess reset tokens without being blocked or slowed down by the system's rate limiter. While the high complexity of the tokens makes a successful guess unlikely, a successful exploit could allow an attacker to take over user or administrator accounts.

Technical details

FOSSBilling prior to version 0.8.0 implements rate limiting only within its API controller (/api/*), leaving non-API routes unprotected. The password reset confirmation (/client/reset-password-confirm/:hash), admin reset (/staff/email/:hash), and email confirmation (/client/confirm-email/:hash) endpoints are handled by a separate controller path that lacks middleware for request throttling or lockout. These endpoints act as an oracle, returning an HTTP 200 for valid tokens and an HTTP 302 for invalid ones. Although the tokens use SHA-256 with 256 bits of entropy and expire after 15 minutes, the lack of server-side throttling allows for unlimited automated probing. The issue is resolved in version 0.8.0 by improving the rate limit system architecture.

Affected products

  • FOSSBilling FOSSBilling 0.1.0 to 0.7.2

Timeline

  • 2026-05-28: patched: Version 0.8.0 released
  • 2026-05-30: advisory: GitHub Security Advisory published
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats