CVE-2026-43924: FOSSBilling has an open redirect via administrator-configured redirect targets

Published Jun 3, 2026
·
Updated

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL scheme of administrator-configured destination URLs before storing or issuing redirects. This allows arbitrary external URLs to be configured as redirect targets, creating an open redirect vulnerability exploitable for phishing attacks. Users following a legitimate FOSSBilling URL can be silently redirected to an attacker-controlled external site. The redirect is issued as a 301 (Moved Permanently) response, which browsers cache persistently, amplifying the impact. Exploitation requires administrator privileges to create or modify redirect entries, limiting practical attack scenarios to multi-admin environments or compromised admin accounts. Version 0.8.0 fixes the issue. Some workarounds are available. Restrict admin access to the Redirect module to trusted administrators only and/or audit existing redirect entries in the database (the extensionmeta table with extension = 'modredirect') for any unexpected or external target URLs.

Affected Software

1 affected component
fossbilling fossbilling<0.8.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FOSSBilling to a version that resolves this vulnerability.

    Fixed in 0.8.0
  2. Configuration

    In FOSSBilling, upgrade to v0.8.0 where the Redirect module validates the URL scheme of administrator-configured destination URLs before storing/issuing redirects (prior to 0.8.0 this validation did not occur).

    FOSSBilling Redirect module redirect targets validation (URL scheme) = enabled
  3. Compensating control

    Restrict administrator access to the Redirect module to trusted administrators only.

  4. Compensating control

    Audit existing redirect entries in the database table `extension_meta` where `extension = 'mod_redirect'` for unexpected or external target URLs.

Event History

Jun 3, 2026
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-43924?

CVE-2026-43924 has a medium severity rating of 4.8 based on the CVSS score.

2

How do I fix CVE-2026-43924?

To fix CVE-2026-43924, upgrade to FOSSBilling version 0.8.0 or later, where the redirect URL validation has been implemented.

3

What is the impact of CVE-2026-43924?

CVE-2026-43924 allows an attacker to configure arbitrary external URLs as redirect targets, which can lead to phishing or other malicious activities.

4

Who is affected by CVE-2026-43924?

CVE-2026-43924 affects all users of FOSSBilling versions prior to 0.8.0 that utilize the Redirect module.

5

What is the description of CVE-2026-43924?

CVE-2026-43924 describes a vulnerability in FOSSBilling that involves an open redirect due to insufficient validation of URL schemes for administrator-configured redirect targets.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2026-43924 - FOSSBilling has an open redirect via administrator-configured redirect targets - SecAlerts