CVE-2026-53640: FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data

Published Jul 6, 2026
·
Updated

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff accounts may read sensitive data via admin API endpoints that lack permission checks. While sibling write endpoints correctly enforce fine-grained permissions, the corresponding read endpoints have no authorization guards. Version 0.8.0 contains a fix. Some workarounds are available. Restrict staff accounts to only those who need access to sensitive data and/or use a reverse proxy or WAF to restrict access to the affected endpoints.

Affected Software

1 affected component
fossbilling fossbilling<0.8.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FOSSBilling to a version that resolves this vulnerability.

    Fixed in 0.8.0
  2. Compensating control

    Use a reverse proxy or WAF to restrict access to the affected read-only admin API endpoints that lack authorization checks.

Event History

Jul 6, 2026
CVE Published
via MITRE·10:30 PM
Data Sourced
via MITRE·10:30 PM
DescriptionWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-53640?

CVE-2026-53640 has a risk score of 47, indicating a moderate severity level due to missing authorization checks.

2

How do I fix CVE-2026-53640?

To fix CVE-2026-53640, upgrade your FOSSBilling installation to version 0.8.0 or later, which implements the necessary authorization checks.

3

What data is exposed due to CVE-2026-53640?

CVE-2026-53640 exposes sensitive staff, client, and redirect data to low-privileged staff accounts through admin API endpoints.

4

Which versions of FOSSBilling are affected by CVE-2026-53640?

CVE-2026-53640 affects all versions of FOSSBilling prior to version 0.8.0.

5

What type of vulnerability is CVE-2026-53640 classified as?

CVE-2026-53640 is classified as an information leakage vulnerability due to missing authorization checks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203