Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-43918— Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows

AI Predicted 5.4 Difficulty: Moderate EPSS 0.24% · P15

Possible ATT&CK Techniques 1AI

T1078 · Valid Accounts

Affected Version Matrix 1

VendorProductVersion RangeStatus
FOSSBillingFOSSBilling< 0.8.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-43918

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows
Source: CVE Program / CVE List V5
Vulnerability Description
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing authenticated sessions are not invalidated. The session identity loaders in src/di.php (loggedin_client and loggedin_admin) only reject sessions if the backing account record no longer exists in the database. They do not verify that the account's status is still active. This allows a suspended or deactivated user to retain full access until their session naturally expires. This issue has been fixed in version 0.8.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的会话过期机制
Source: CVE Program / CVE List V5
Vulnerability Title
FOSSBilling 会话机制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
fossbilling是fossbilling团队开源的一种高效计费和客户管理方案。 FOSSBilling 0.8.0之前版本存在会话机制问题漏洞,该漏洞源于会话身份加载器未验证账户状态是否仍为激活状态,当账户被暂停或标记为非活动时,已存在的认证会话未被撤销,导致被暂停或停用的用户可保留完全访问权限直至会话自然过期。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
FOSSBillingFOSSBilling < 0.8.0 -

II. Public POCs for CVE-2026-43918

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-43918

登录查看更多情报信息。

Vendor Advisories for CVE-2026-43918 (1)

Vendor Pages for CVE-2026-43918 (1)

Same Patch Batch · FOSSBilling · 2026-07-06 · 17 CVEs total

CVE-2026-42341FOSSBilling has an unauthenticated payment bypass via IPN callback forgery
CVE-2026-42331FOSSBilling missing authorization in guest Invoice API endpoints
CVE-2026-33734FOSSBilling has improper SQL neutralization in `Massmailer` recipient filters
CVE-2026-43921FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serialization
CVE-2026-43927FOSSBilling has race condition in cart checkout that bypasses promo code usage limits
CVE-2026-43925FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized
CVE-2026-43928FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayme
CVE-2026-53640FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive
CVE-2026-53641FOSSBilling has stored XSS in client email views via unescaped content in JavaScript templ
CVE-2026-53645FOSSBilling's missing self-edit prevention in staff permission management allows persisten
CVE-2026-53646FOSSBilling: Client password reset token reuse allows persistent account takeover
CVE-2026-53643FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin
CVE-2026-53644FOSSBilling's missing order-state validation allows clients to read and reset API key secr
CVE-2026-53642FOSSBilling: Unverified clients can access client-area pages when email confirmation is re
CVE-2026-53647FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Servi
CVE-2026-53648FOSSBilling: Downloadable product files can be overwritten through filename collisions

IV. Related Vulnerabilities

V. Comments for CVE-2026-43918

No comments yet


Leave a comment