Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-42341: FOSSBilling Payment Bypass via Fake Payment Request
CVE-2026-42341
CVE-2026-42341
Summary
FOSSBilling's payment system has a weakness that allows an attacker to trick the system into paying invoices without actually paying. This can happen if the Custom payment adapter is enabled and an attacker sends a fake payment request. To protect your business, disable the Custom payment gateway if not needed and restrict access to the payment endpoint at the web server level.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| fossbilling | fossbilling | >= 0.6.0, < 0.8.0 |
Original title
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. Wh...
Original description
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment, by sending a single crafted HTTP request. Version 0.8.0 patches the issue. Some workarounds are available. Disable the Custom payment gateway if not actively needed and/or restrict access to `/ipn.php` at the web server level (e.g., via IP allowlisting), noting that this may interfere with legitimate payment callback processing.
nvd CVSS4.0
9.2
Vulnerability type
CWE-306
Missing Authentication for Critical Function
CWE-346
Published: 6 Jul 2026 · Updated: 8 Jul 2026 · First seen: 6 Jul 2026