Unrated severityNVD Advisory· Published Jul 6, 2026· Updated Jul 7, 2026
FOSSBilling has an unauthenticated payment bypass via IPN callback forgery
CVE-2026-42341
Description
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment, by sending a single crafted HTTP request. Version 0.8.0 patches the issue. Some workarounds are available. Disable the Custom payment gateway if not actively needed and/or restrict access to /ipn.php at the web server level (e.g., via IP allowlisting), noting that this may interfere with legitimate payment callback processing.
Affected products
1- Range: 0.6.0 - 0.7.2
Patches
Vulnerability mechanics
References
1- github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-5493-9m76-2qrrmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.