CVE-2026-23513EPSS p30.4%
CVE-2026-23513CVE-2026-23513
Description
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-construction flaw in client list endpoints allowed authenticated clients to bypass tenant scoping and retrieve other clients’ data. Details
In ServiceTransaction::getSearchQuery() and Order\Service::getSearchQuery(), OR-based search/action filters were appended without grouping, allowing SQL operator precedence to evaluate OR clauses independently of the enforced client_id constraint. Crafted requests could therefore return records and metadata belonging to other clients, including identifiers, amounts, status, timestamps, and related fields. This issue was fixed in version 0.8.0.
Scoring
| EPSS | 0.39% probability of exploitation · percentile 30.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-06-26 |