Information Disclosure in FOSSBilling Client Management System
CVE-2026-27708
7.1HIGH
What is CVE-2026-27708?
FOSSBilling, a popular open-source billing and client management system, has a vulnerability in its Servicecustom Client API's __call method in versions 0.7.2 and earlier. This method accepts an order_id parameter, allowing authenticated clients to access orders without verifying ownership. This oversight makes it possible for attackers to exploit sequential order IDs, leading to potential exposure of sensitive client data including personally identifiable information (PII) such as names, emails, phone numbers, and company details. The issue has been addressed in version 0.8.0, emphasizing the importance of updating to the latest release to safeguard against unauthorized data access.
Affected Version(s)
FOSSBilling < 0.8.0
