CVE-2026-27708 - FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access

CVE Advisories
Post Reply
Starburst-David
Posts: 289
Joined: Wed Feb 11, 2026 8:31 pm

CVE-2026-27708 - FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access

Post by Starburst-David »

CVE ID: CVE-2026-27708
Published: June 24, 2026
Description: FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter and fetches the associated order without verifying the authenticated client owns it, potentially exposing cross-client data through IDOR. An authenticated client can access any other client's custom service by guessing sequential order IDs. This can lead to a confidentiality breach — attackers can read client PII (name, email, phone, address, company details, VAT number) and service configuration data belonging to other clients. This issue has been fixed in version 0.8.0.
Severity: 0.0 | NA

More Information:
https://cvefeed.io/vuln/detail/CVE-2026-27708
 

POSTREACT(ions) SUMMARY

Post Reply

Return to “CVE Advisories”