CVE-2026-43920General

LOWCVSS 6.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible without authentication, which allowed unauthenticated remote users to trigger update patch routines that modify configuration files, execute database schema changes, perform filesystem mutations, and clear caches. The /run-patcher endpoint executes privileged maintenance operations - configuration migrations, database patch execution (including ALTER TABLE, DROP TABLE, UPDATE statements), filesystem deletions and renames, and cache clearing - without requiring administrator authentication, CSRF validation, or CLI context. An unauthenticated remote attacker can trigger these operations by sending a simple HTTP GET request to /run-patcher, which can be abused for denial-of-service attacks. Certain patches (e.g., batch token regeneration for all admin and client accounts in patch 53, and session invalidation) are disruptive even when re-executed against an already-patched instance. Repeated or concurrent requests may also cause inconsistent database state. This issue has been fixed in version 0.8.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-26: 3Technical Details · 2026-06-26: 106-26
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-43920 Unauthenticated Remote Access to Privileged Maintenance Endpoint in FOSSBilling 0.5.4-0.7.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43920

    Post summary

    The entry announces CVE-2026-43920, a remote access vulnerability in FOSSBilling, but provides no exploit code, patch, or evidence of active attacks.

    0000097
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-43920 FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was acc… https://www.cve.org/CVERecord?id=CVE-2026-43920 ----- Traducción: CVE-2026-43920 FOS… http://infoflow.cloud`

    Post summary

    The message announces CVE-2026-43920 for FOSSBilling with a link to its CVE record but provides no further technical or exploitation information.

    0000034
    89 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-43920 FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was acc… https://www.cve.org/CVERecord?id=CVE-2026-43920

    Post summary

    The post merely references CVE-2026-43920 with a brief mention of the affected endpoint, offering no additional technical details, PoC, exploitation evidence, or remediation information.

    00000762
    57.7K followersView on X

Explore more