Query Construction Flaw in FOSSBilling's Client Management System
CVE-2026-23513
7.1HIGH
What is CVE-2026-23513?
FOSSBilling, a free and open-source billing and client management system, suffered from a query construction flaw in its client list endpoints in versions up to 0.7.2. This vulnerability allowed authenticated clients to bypass tenant restrictions, thus exposing sensitive client data from other accounts. Specifically, due to SQL operator precedence issues, crafted requests could execute OR-based search actions without proper grouping, enabling access to confidential details like identifiers, amounts, status, timestamps, and related metadata. This issue was resolved in version 0.8.0, underscoring the necessity for vigilant security practices and timely updates.
Affected Version(s)
FOSSBilling < 0.8.0
