CVE-2026-53643 Details
Description
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unauthorized actions via admin API endpoints. The root cause is a combination of the `can_always_access` module flag (which grants all staff access to certain modules) and insufficient permission checks or unsafe parameter handling on individual endpoints. Version 0.8.0 contains a fix. Some workarounds are available. Restrict staff accounts to only those who need access to sensitive settings and/or use a reverse proxy or WAF to restrict access to the affected endpoints to trusted IP addresses or higher-privilege roles.
A vulnerability in FOSSBilling versions prior to 0.8.0 allows low-privileged staff accounts to perform unauthorized actions through admin API endpoints. This issue arises from the 'can_always_access' module flag, which grants all staff access to certain modules, combined with inadequate permission checks and unsafe parameter handling on specific endpoints. As a result, affected staff can access sensitive system settings, read decrypted extension configurations, expose environment details, manipulate system cron executions, manage global language packs, disrupt session management for administrators and clients, and interfere with password recovery processes.
Users can upgrade to FOSSBilling version 0.8.0, which addresses these vulnerabilities. Additionally, staff accounts should be restricted to those who need access to sensitive settings, and a reverse proxy or Web Application Firewall (WAF) can be used to limit access to the affected endpoints from trusted IP addresses or higher-privilege roles.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 6, 2026CISA-ADP
Assessed Jul 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-563q-g4r4-6f9m | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| FOSSBilling | <= 0.7.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 7, 2026 | CVE Modified | CISA-ADP |
| Jul 6, 2026 | New CVE Received | [email protected] |
Volerion