Junglewise Threat Intelligence

CVE-2026-53642: FOSSBilling incorrect authorization in client area access control

CVE-2026-53642 · Severity: info · CVSS 5.3 · Published 2026-07-06

Technologies: FOSSBilling. Vendors: FOSSBilling.

Executive brief

FOSSBilling is an open-source platform used by businesses to manage client billing, invoices, and support services. A security flaw allows newly registered users to bypass email verification requirements and access sensitive account areas. An unverified user can view financial data, transaction histories, and active service details that should remain locked until their identity is confirmed.

Technical details

An incorrect authorization vulnerability exists in FOSSBilling's page-side enforcement logic within src/di.php. While API endpoints are correctly restricted via an allowlist, the routing logic for web pages uses an overly permissive check that allows any request path starting with '/client' for unverified users (email_approved = 0). This allows authenticated but unverified attackers to bypass the email confirmation gate and access sensitive routes such as /client/balance, /client/invoice, and /client/support/tickets. The vulnerability was introduced in PR #1534 and is resolved in version 0.8.0 by tightening the path-based access controls.

Affected products

  • FOSSBilling FOSSBilling >= 0.5.6, <= 0.7.2

Timeline

  • 2026-06-12: advisory: GitHub Security Advisory published
  • 2026-07-06: disclosed: NVD publication date

References

Related threats