CVE-2026-23513 PUBLISHED

FOSSBilling: Broken Authorization in Client Transaction and Order Listings

Assigner: GitHub_M
Reserved: 13.01.2026 Published: 23.06.2026 Updated: 23.06.2026

FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-construction flaw in client list endpoints allowed authenticated clients to bypass tenant scoping and retrieve other clients’ data. Details In ServiceTransaction::getSearchQuery() and Order\Service::getSearchQuery(), OR-based search/action filters were appended without grouping, allowing SQL operator precedence to evaluate OR clauses independently of the enforced client_id constraint. Crafted requests could therefore return records and metadata belonging to other clients, including identifiers, amounts, status, timestamps, and related fields. This issue was fixed in version 0.8.0.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor FOSSBilling
Product FOSSBilling
Versions
  • Version < 0.8.0 is affected

References

Problem Types

  • CWE-863: Incorrect Authorization CWE