Description
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present in other invoice-related endpoints, allowing an unauthenticated user with knowledge of an invoice hash to modify the payment gateway associated with an unpaid invoice. An attacker who obtains an invoice hash, which may leak through shared URLs, referrer headers, or email links, can change the `gateway_id` on an unpaid invoice to any payment gateway configured in the system. This does not allow redirecting payments to an arbitrary external endpoint, as the gateway must already be installed and configured by an administrator. The practical impact is further limited by the `invoice_accessible_from_hash` system setting. Version 0.8.0 contains a patch. No known workarounds are available.
Published: 2026-07-06
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FOSSBilling, suffers from missing authentication and authorization in the guest invoice/update API. An unauthenticated user who knows or can guess an invoice hash can change the gateway_id field on any unpaid invoice. The vulnerability is an instance of CWE‑306 (Missing Authentication) and CWE‑863 (Missing Authorization for Modification). The attacker to billing the new gateway is misconfigured or malicious.

Affected Systems

All releases of FOSSBilling before version 0.8.0 invoice/update route that accepts requests containing an invoice hash. Administrators should verify which of their deployed versions are impacted and apply the patch released in 0.8.0.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity while the EPSS score of < 1% suggests a very low probability of exploitation. The likely attack vector is API, inferred from the description. An attacker may obtain an invoice hash through shared URLs, referrer headers, or email links. The impact is bounded by the requirement that the target gateway be pre‑installed, but the unintended gateway switch can still disrupt payment processing or enable unauthorized transaction routing. The vulnerability is not listed in the CISA KEV catalog and is mitigated by disabling the invoice_accessible_from_hash setting if it is not required.

Generated by OpenCVE AI on July 26, 2026 at 20:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FOSSBilling to version 0.8.0 or later.
  • Disable the invoice_accessible_from_hash setting if it is not needed.
  • Restrict gateway configuration permissions to trusted administrators and audit gateway usage.

Generated by OpenCVE AI on July 26, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Fossbilling
Fossbilling fossbilling
Vendors & Products Fossbilling
Fossbilling fossbilling

Mon, 06 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title FOSSBilling has incorrect authorization in invoice Guest API endpoints FOSSBilling missing authorization in guest Invoice API endpoints

Mon, 06 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present in other invoice-related endpoints, allowing an unauthenticated user with knowledge of an invoice hash to modify the payment gateway associated with an unpaid invoice. An attacker who obtains an invoice hash, which may leak through shared URLs, referrer headers, or email links, can change the `gateway_id` on an unpaid invoice to any payment gateway configured in the system. This does not allow redirecting payments to an arbitrary external endpoint, as the gateway must already be installed and configured by an administrator. The practical impact is further limited by the `invoice_accessible_from_hash` system setting. Version 0.8.0 contains a patch. No known workarounds are available.
Title FOSSBilling has incorrect authorization in invoice Guest API endpoints
Weaknesses CWE-306
CWE-863
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N'}


Subscriptions

Fossbilling Fossbilling
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-07T13:51:59.385Z

Reserved: 2026-04-26T13:26:14.513Z

Link: CVE-2026-42331

cve-icon Vulnrichment

Updated: 2026-07-07T13:51:53.846Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:15:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-863

    Incorrect Authorization