Junglewise Threat Intelligence

CVE-2026-53643: FOSSBilling authorization bypass in admin API endpoints

CVE-2026-53643 · Severity: info · CVSS 8.7 · Published 2026-07-06

Technologies: FOSSBilling. Vendors: FOSSBilling.

Executive brief

FOSSBilling is an open-source platform used by businesses to manage client billing, support tickets, and service provisioning. A security flaw allows staff members with low-level access (such as basic support agents) to view sensitive company data, including bank details and API keys for payment gateways. Additionally, these users can disrupt operations by forcing other administrators to log out or triggering automated billing processes prematurely.

Technical details

Multiple authorization flaws exist in FOSSBilling's admin API due to the 'can_always_access' module flag in 'src/modules/Staff/Service.php', which bypasses module-level permission checks for all authenticated staff. Combined with missing endpoint-level validation, low-privileged attackers can exploit various endpoints: '/api/admin/system/get_params' and '/api/admin/extension/config_get' leak system settings and decrypted extension secrets (SMTP/API keys); '/api/admin/profile/destroy_sessions' allows arbitrary session termination; and '/api/admin/system/messages' can be used to trigger system cron jobs. Furthermore, incomplete field protection in 'system/update_params' allows unauthorized modification of bank-related configuration fields. These issues are resolved in version 0.8.0.

Affected products

  • FOSSBilling FOSSBilling < 0.8.0

Timeline

  • 2026-06-12: advisory: GitHub security advisory published
  • 2026-07-06: disclosed: NVD publication date

References

Related threats