Information Disclosure in FOSSBilling Client Management System
CVE-2026-27708

7.1HIGH

Key Information:

Vendor
CVE Published:
24 June 2026

What is CVE-2026-27708?

FOSSBilling, a popular open-source billing and client management system, has a vulnerability in its Servicecustom Client API's __call method in versions 0.7.2 and earlier. This method accepts an order_id parameter, allowing authenticated clients to access orders without verifying ownership. This oversight makes it possible for attackers to exploit sequential order IDs, leading to potential exposure of sensitive client data including personally identifiable information (PII) such as names, emails, phone numbers, and company details. The issue has been addressed in version 0.8.0, emphasizing the importance of updating to the latest release to safeguard against unauthorized data access.

Affected Version(s)

FOSSBilling < 0.8.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.