Junglewise Threat Intelligence

CVE-2026-53644: FOSSBilling authorization bypass in Serviceapikey module

CVE-2026-53644 · Severity: info · CVSS 8.6 · Published 2026-07-06

Technologies: FOSSBilling. Vendors: FOSSBilling.

Executive brief

FOSSBilling, an open-source billing and client management platform, contains a flaw that allows customers to access and change service credentials even after their account has been suspended or canceled. This means a user who should no longer have access to a service can still view their old API keys or generate new ones, potentially maintaining unauthorized access to connected third-party systems. This bypasses the security controls intended to cut off service access during account termination or suspension.

Technical details

An authorization bypass exists in FOSSBilling due to missing order-state validation in the Serviceapikey module. While the frontend UI correctly hides management options for non-active orders (e.g., suspended or canceled), the underlying API endpoints `/api/client/order/service` and `/api/client/serviceapikey/reset` do not verify if an order is active before processing requests. An authenticated attacker can bypass the UI restrictions to retrieve cleartext API keys or rotate them, potentially maintaining access to downstream services that trust these credentials. The issue is resolved in version 0.8.0 by implementing the existing `isActive()` helper check within the affected API controllers.

Affected products

  • FOSSBilling FOSSBilling 0.5.3 - 0.7.2

Timeline

  • 2026-06-12: advisory: GitHub Security Advisory published
  • 2026-07-06: disclosed: NVD publication date

References

Related threats