CVE-2026-43920

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible without authentication, which allowed unauthenticated remote users to trigger update patch routines that modify configuration files, execute database schema changes, perform filesystem mutations, and clear caches. The /run-patcher endpoint executes privileged maintenance operations - configuration migrations, database patch execution (including ALTER TABLE, DROP TABLE, UPDATE statements), filesystem deletions and renames, and cache clearing - without requiring administrator authentication, CSRF validation, or CLI context. An unauthenticated remote attacker can trigger these operations by sending a simple HTTP GET request to /run-patcher, which can be abused for denial-of-service attacks. Certain patches (e.g., batch token regeneration for all admin and client accounts in patch 53, and session invalidation) are disruptive even when re-executed against an already-patched instance. Repeated or concurrent requests may also cause inconsistent database state. This issue has been fixed in version 0.8.0.
CVSS

No CVSS.

Configurations

No configuration.

History

26 Jun 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-26 00:16

Updated : 2026-06-26 16:10


NVD link : CVE-2026-43920

Mitre link : CVE-2026-43920

CVE.ORG link : CVE-2026-43920


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function