CVE-2026-42331: FOSSBilling missing authorization in guest Invoice API endpoints

Published Jul 6, 2026
·
Updated

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present in other invoice-related endpoints, allowing an unauthenticated user with knowledge of an invoice hash to modify the payment gateway associated with an unpaid invoice. An attacker who obtains an invoice hash, which may leak through shared URLs, referrer headers, or email links, can change the gatewayid on an unpaid invoice to any payment gateway configured in the system. This does not allow redirecting payments to an arbitrary external endpoint, as the gateway must already be installed and configured by an administrator. The practical impact is further limited by the invoiceaccessiblefromhash system setting. Version 0.8.0 contains a patch. No known workarounds are available.

Affected Software

1 affected component
FOSSBilling<0.8.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FOSSBilling to a version that resolves this vulnerability.

    Fixed in 0.8.0

Event History

Jul 6, 2026
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-42331?

The severity of CVE-2026-42331 is rated as high with a score of 7.7.

2

How do I fix CVE-2026-42331?

To fix CVE-2026-42331, upgrade FOSSBilling to version 0.8.0 or later where the authorization checks have been implemented.

3

What type of vulnerability is CVE-2026-42331?

CVE-2026-42331 is classified as a missing authorization vulnerability affecting the Guest API invoice/update endpoint.

4

Who is affected by CVE-2026-42331?

Any FOSSBilling users prior to version 0.8.0 who expose the Guest API invoice/update endpoint are affected by CVE-2026-42331.

5

What can an attacker do with CVE-2026-42331?

An attacker can modify payment details if they possess knowledge of an invoice hash due to the missing authorization in the API.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203