CVE-2026-42331
Last modified
CVE-2026-42331 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present in other invoice-related endpoints, allowing an unauthenticated user with knowledge of an invoice hash to modify the payment gateway associated with an unpaid invoice. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present in other invoice-related endpoints, allowing an unauthenticated user with knowledge of an invoice hash to modify the payment gateway associated with an unpaid invoice. An attacker who obtains an invoice hash, which may leak through shared URLs, referrer headers, or email links, can change the `gateway_id` on an unpaid invoice to any payment gateway configured in the system. This does not allow redirecting payments to an arbitrary external endpoint, as the gateway must already be installed and configured by an administrator. The practical impact is further limited by the `invoice_accessible_from_hash` system setting. Version 0.8.0 contains a patch. No known workarounds are available.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| FOSSBilling | FOSSBilling | < 0.8.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-42331?
How severe is CVE-2026-42331?
How do I fix CVE-2026-42331?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-42321GLPI is a free asset and IT management software package. Sta…8.4
- CVE-2026-42326ImageMagick is free and open-source software used for editin…5.1
- CVE-2026-42327rust-openssl provides OpenSSL bindings for the Rust programm…8.7
- CVE-2026-42328go-ipld-prime is an implementation of the InterPlanetary Lin…6.2
- CVE-2026-42329Iris is a web collaborative platform that helps incident res…4.7
- CVE-2026-4233A vulnerability was identified in ThingsGateway 12. This aff…4.3
- CVE-2026-42333Quarkus OpenAPI Generator is Quarkus' extensions for generat…6.3
- CVE-2026-42334Mongoose is a MongoDB object modeling tool designed to work …7.5
- CVE-2026-42335MaxKB is an open-source AI assistant for enterprise. Prior t…6.3
- CVE-2026-42336MaxKB is an open-source AI assistant for enterprise. MaxKB 2…5.1
- CVE-2026-42337MaxKB is an open-source AI assistant for enterprise. MaxKB 2…5.3
- CVE-2026-42338ip-address is a library for parsing and manipulating IPv4 an…6.1
Are you affected by CVE-2026-42331?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
