CVE-2026-33543: FOSSBilling: Authentication bypass allows unauthenticated administrator creation

Published Jun 24, 2026
·
Updated

FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/create, intended for initial administrator bootstrap. Due to a flawed admin-existence check, the endpoint remains usable after an administrator already exists. The flawed guard check uses iscountable() on a value that returns a ModelAdmin object or null rather than a countable type, causing the expression to always evaluate as true and bypass the intended protection. As a result, an attacker can reach the unprotected endpoint to create a new administrator account and immediately authenticate, gaining a fully privileged admin session even when an admin already exists. This issue has been fixed in version 0.8.0.

Affected Software

1 affected component
fossbilling fossbilling<=0.7.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FOSSBilling to a version that resolves this vulnerability.

    Fixed in 0.8.0
  2. Compensating control

    Restrict or block access to the guest bootstrap endpoint /api/guest/staff/create on FOSSBilling versions 0.7.2 and prior to prevent unauthenticated administrator creation/authentication bypass.

Event History

Jun 24, 2026
CVE Published
via MITRE·09:01 PM
Data Sourced
via MITRE·09:01 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-33543?

The severity of CVE-2026-33543 is critical with a CVSS score of 9.3.

2

How do I fix CVE-2026-33543?

To fix CVE-2026-33543, upgrade to FOSSBilling version 0.8.0 or later.

3

What issue does CVE-2026-33543 present?

CVE-2026-33543 allows for an authentication bypass that enables unauthenticated creation of administrators.

4

Which versions are affected by CVE-2026-33543?

Versions of FOSSBilling up to and including 0.7.2 are affected by CVE-2026-33543.

5

What component of FOSSBilling is impacted by CVE-2026-33543?

CVE-2026-33543 impacts the guest API endpoint intended for initial administrator bootstrap in FOSSBilling.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203