CVE-2026-42341 - FOSSBilling has an unauthenticated payment bypass via IPN callback forgery

CVE Advisories
Post Reply
Starburst-David
Posts: 286
Joined: Wed Feb 11, 2026 8:31 pm

CVE-2026-42341 - FOSSBilling has an unauthenticated payment bypass via IPN callback forgery

Post by Starburst-David »

CVE ID: CVE-2026-42341
Published: July 6, 2026
Description: FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment, by sending a single crafted HTTP request. Version 0.8.0 patches the issue. Some workarounds are available. Disable the Custom payment gateway if not actively needed and/or restrict access to `/ipn.php` at the web server level (e.g., via IP allowlisting), noting that this may interfere with legitimate payment callback processing.
Severity: 9.2 | CRITICAL

More Information:
https://cvefeed.io/vuln/detail/CVE-2026-42341
 

POSTREACT(ions) SUMMARY

Post Reply

Return to “CVE Advisories”