CVE-2026-28496: FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE

Published Jun 23, 2026
·
Updated

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnerability in the template rendering system. Administrators with access to features that render Twig templates (email templates, mass mail campaigns, custom payment adapters, and the stringrender API endpoint) can inject arbitrary Twig expressions, leading to information disclosure and remote code execution. The vulnerability exists because Twig templates are rendered without a sandbox, allowing access to the full Twig environment, API context, and the application's dependency injection container. Version 0.8.0 patches the issue. Some workarounds are available. Audit existing email templates for suspicious Twig expressions, rotate all admin and client API tokens, and/or block external access to /api/system/ at reverse proxy/WAF to mitigate chaining with GHSA-78x5-c8gw-8279.

Affected Software

1 affected component
fossbilling fossbilling<0.8.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FOSSBilling to a version that resolves this vulnerability.

    Fixed in 0.8.0
  2. Compensating control

    Block external access to /api/system/* at the reverse proxy or WAF to mitigate chaining with GHSA-78x5-c8gw-8279.

  3. Operational

    Audit existing Twig-using features for suspicious Twig expressions: email templates, mass mail campaigns, custom payment adapters, and the `string_render` API endpoint. Remove or sanitize any untrusted or malicious expressions.

  4. Operational

    Rotate all admin and client API tokens.

Event History

Jun 23, 2026
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-28496?

CVE-2026-28496 has a risk rating of 66, indicating a moderate to high severity level.

2

What is CVE-2026-28496 about?

CVE-2026-28496 is a server-side template injection vulnerability in FOSSBilling's Twig template rendering that can lead to information disclosure and remote code execution.

3

How do I fix CVE-2026-28496?

To fix CVE-2026-28496, ensure that you upgrade to FOSSBilling version 0.8.0 or later.

4

Who is affected by CVE-2026-28496?

Administrators using FOSSBilling versions prior to 0.8.0 with access to features that render Twig templates are affected by CVE-2026-28496.

5

What can be exploited through CVE-2026-28496?

CVE-2026-28496 can be exploited to potentially allow unauthorized access to sensitive information and execute arbitrary code on the server.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203