Unauthenticated Access Vulnerability in FOSSBilling Client Management System
CVE-2026-43920

6.9MEDIUM

Key Information:

Vendor
CVE Published:
25 June 2026

What is CVE-2026-43920?

FOSSBilling, a free and open-source billing and client management system, has a vulnerability that allows unauthenticated remote users to access the /run-patcher maintenance endpoint without proper authentication. This access enables attackers to execute critical operations such as configuration migrations, database schema alterations, filesystem changes, and cache clearing through simple HTTP GET requests. Notably, these operations are conducted without requiring admin credentials or CSRF validation, elevating the risk of denial-of-service attacks and causing potential inconsistencies in the database state. This vulnerability affects FOSSBilling versions 0.5.4 to 0.7.2 and has been addressed in version 0.8.0.

Affected Version(s)

FOSSBilling >= 0.5.4, < 0.8.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.