FOSSBilling disclosed two critical vulnerabilities that can be chained to give unauthenticated attackers administrative access and remote code execution on billing platforms used by hosting providers. CVE-2026-27604 is an authorization bypass in versions 0.5.4 through 0.7.2 that lets remote attackers reach privileged /api/system/* endpoints because the system API role is incorrectly mapped to the cron admin identity. CVE-2026-28496 is a Twig server-side template injection flaw affecting versions 0.1.0 through 0.7.2, where templates are rendered without a sandbox, exposing the Twig environment, API context, and the dependency injection container.
Researchers said the chain allows attackers to read and modify databases, enumerate administrators, create admin accounts, generate privileged API tokens, poison the Symfony cache used by the extension installer, and install a malicious module to execute code as the web server user. The exposure is significant because affected instances may hold customer PII, billing records, payment processor secrets, hosting control panel credentials, sessions, and API tokens. FOSSBilling patched both issues in version 0.8.0 and advised defenders to block external access to /api/system/*, restrict API access to trusted IPs, rotate admin and client API tokens, invalidate active sessions, reset high-privilege credentials, audit templates for malicious Twig expressions, and review logs for suspicious /api/system/ activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
CVE feed entries were published for the FOSSBilling authorization bypass and Twig SSTI vulnerabilities, assigning severity and summarizing affected versions, exploitation conditions, and mitigations.
VulnCheck publicly disclosed an unauthenticated remote code execution chain in FOSSBilling that combines CVE-2026-27604 with CVE-2026-28496 to reach admin functions, poison cache, install a malicious module, and execute code.
FOSSBilling published GitHub security advisories GHSA-78x5-c8gw-8279 for the auth bypass and GHSA-57mv-jm88-66jc for the Twig SSTI/RCE issue, documenting impact, affected versions, and mitigations.
FOSSBilling version 0.8.0 fixed CVE-2026-27604 and CVE-2026-28496. VulnCheck explicitly states this release occurred on 2026-05-28.
According to VulnCheck, FOSSBilling patched the reported issues upstream across April and May 2026 before public disclosure.
VulnCheck's timeline says the vulnerabilities were reported in April 2026, beginning coordinated disclosure for the auth bypass and Twig SSTI issues.
VulnCheck's disclosure timeline states the authorization bypass flaw later tracked as CVE-2026-27604 was introduced in July 2023.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.