FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest serviceapikey/get_info API endpoint is accessible without authentication. Any caller with a valid API key can retrieve all custom configuration parameters (custom_* fields) stored in the key's database record. These custom fields are populated by billing administrators and can contain business-sensitive data such as pricing tiers, feature flags, rate limits, expiry overrides, or access scope data. Version 0.8.0 patches the issue. Some workarounds are available. Administrators can avoid storing sensitive data in custom_* API key configuration fields, monitor API logs for suspicious calls to /api/guest/serviceapikey/get_info, and/or disable the Serviceapikey module if not in active use.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small standalone Python PoC named FOSKiller for two FOSSBilling vulnerabilities affecting versions up to 0.7.2. Structure is minimal: one main script (fossbilling_poc.py), a README with vulnerability and usage documentation, requirements.txt, and .gitignore. The Python script is the operational entry point and includes dependency bootstrapping, colored console output, HTTP session creation with optional proxy support, version detection/range checking, per-CVE execution paths, summary reporting, optional JSON output saving, and exit codes based on vulnerability findings. Main exploit capabilities: 1) CVE-2026-53647: tests/exploits unauthenticated disclosure of service API key configuration via the guest API endpoint /api/guest/serviceapikey/get_info. README states this can expose custom fields, API credentials, hostnames, and passwords when a valid API key is supplied. 2) CVE-2026-53646: tests/exercises password reset token reuse by interacting with guest password reset endpoints. The documented chain is repeated reset issuance followed by reuse of an older token to set a chosen password, enabling potential persistent account takeover. The exploit is not framework-based and is more than a detector: it contains active exploitation logic for both issues, though it remains a PoC rather than a generalized weaponized toolkit. It uses Python requests with TLS verification disabled (verify=False), supports operator-supplied target URL, API key, email, timeout, proxy, output file, check-only mode, exploit mode, and force mode. No hardcoded victim infrastructure, C2, or malware behavior is present; all network interaction is directed at the user-specified FOSSBilling target and its guest API endpoints.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.