CVE-2026-42341
CRITICALFOSSBilling has an unauthenticated payment bypass via IPN callback forgery
Title source: cnaDescription
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment, by sending a single crafted HTTP request. Version 0.8.0 patches the issue. Some workarounds are available. Disable the Custom payment gateway if not actively needed and/or restrict access to `/ipn.php` at the web server level (e.g., via IP allowlisting), noting that this may interfere with legitimate payment callback processing.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-5493-9m76-2qrr
Scores
CVSS v4
9.2
EPSS
0.0018
EPSS Percentile
8.2%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-306
CWE-346
Status
published
Products (1)
FOSSBilling/FOSSBilling
>= 0.6.0, < 0.8.0
Published
Jul 06, 2026
Tracked Since
Jul 07, 2026