NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-23513
Summary

FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-construction flaw in client list endpoints allowed authenticated clients to bypass tenant scoping and retrieve other clients’ data. Details
In ServiceTransaction::getSearchQuery() and Order\Service::getSearchQuery(), OR-based search/action filters were appended without grouping, allowing SQL operator precedence to evaluate OR clauses independently of the enforced client_id constraint. Crafted requests could therefore return records and metadata belonging to other clients, including identifiers, amounts, status, timestamps, and related fields. This issue was fixed in version 0.8.0.

Publication Date June 24, 2026, 6:16 a.m.
Registration Date June 27, 2026, 4:15 a.m.
Last Update June 27, 2026, 12:16 a.m.
Related information, measures and tools
Common Vulnerabilities List