CVE-2026-43928
Last modified
CVE-2026-43928 is a low-severity vulnerability rated 2.3/10 on the CVSS scale. FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment adapter accepts PayPal IPN callbacks and credits the IPN-supplied amount (`mc_gross`) to the client's balance without validating it against the invoice total. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment adapter accepts PayPal IPN callbacks and credits the IPN-supplied amount (`mc_gross`) to the client's balance without validating it against the invoice total. Combined with a $0.05 floating-point epsilon tolerance in the invoice credit-payment logic, this allows a client to underpay an invoice by up to $0.04 and still have it marked as fully paid. Version 0.8.0 patches the issue. There is no effective workaround without modifying the source code. Merchants using the PayPalEmail adapter should monitor IPN transactions for amounts that do not match their corresponding invoice totals, and manually review and refund suspicious payments.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| FOSSBilling | FOSSBilling | < 0.8.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-43928?
How severe is CVE-2026-43928?
How do I fix CVE-2026-43928?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-43920FOSSBilling is a free, open-source billing and client manage…6.9
- CVE-2026-43921FOSSBilling is a free, open-source billing and client manage…8.9
- CVE-2026-43924FOSSBilling is a free, open-source billing and client manage…4.8
- CVE-2026-43925FOSSBilling is a free, open-source billing and client manage…6.9
- CVE-2026-43926FOSSBilling is a free, open-source billing and client manage…6.3
- CVE-2026-43927FOSSBilling is a free, open-source billing and client manage…6.9
- CVE-2026-43929ssrfcheck is a library that checks if a string contains a po…8.2
- CVE-2026-4393Cross-Site Request Forgery (CSRF) vulnerability in Drupal Au…4.3
- CVE-2026-43930Parse Server is an open source backend that can be deployed …5.9
- CVE-2026-43934e107 is a content management system (CMS). Prior to 2.3.4, a…6.5
- CVE-2026-43935e107 is a content management system (CMS). Prior to 2.3.4, a…8.1
- CVE-2026-43936e107 is a content management system (CMS). Prior to 2.3.4, y…4.3
Are you affected by CVE-2026-43928?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
