Unauthenticated Access Vulnerability in FOSSBilling Client Management System
CVE-2026-43920
6.9MEDIUM
What is CVE-2026-43920?
FOSSBilling, a free and open-source billing and client management system, has a vulnerability that allows unauthenticated remote users to access the /run-patcher maintenance endpoint without proper authentication. This access enables attackers to execute critical operations such as configuration migrations, database schema alterations, filesystem changes, and cache clearing through simple HTTP GET requests. Notably, these operations are conducted without requiring admin credentials or CSRF validation, elevating the risk of denial-of-service attacks and causing potential inconsistencies in the database state. This vulnerability affects FOSSBilling versions 0.5.4 to 0.7.2 and has been addressed in version 0.8.0.
Affected Version(s)
FOSSBilling >= 0.5.4, < 0.8.0
