CVE-2026-27708
FOSSBilling
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter and fetches the associated order without verifying the authenticated client owns it, potentially exposing cross-client data through IDOR. An authenticated client can access any other client's custom service by guessing sequential order IDs. This can lead to a confidentiality breach — attackers can read client PII (name, email, phone, address, company details, VAT number) and service configuration data belonging to ot...
- CVSS
- 7.1
- EPSS
- 0.27% 18.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.25