PT-2026-44501 · Unknown · Fossbilling

·

CVE-2026-28496

·

Published

2026-05-26

·

Updated

2026-07-17

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions FOSSBilling versions prior to 0.8.0
Description A Server-Side Template Injection (SSTI) issue exists in the template rendering system. Administrators with access to features that render Twig templates—such as email templates, mass mail campaigns, custom payment adapters, and the string render API endpoint—can inject arbitrary Twig expressions. This occurs because Twig templates are rendered without a sandbox, granting access to the full Twig environment, API context, and the application's dependency injection container, which can lead to information disclosure and remote code execution. Real-world exploitation has been observed in targeted campaigns.
Recommendations Update to version 0.8.0. Audit existing email templates for suspicious Twig expressions. Rotate all admin and client API tokens. Block external access to the /api/system/* endpoint at the reverse proxy or WAF.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28496
GHSA-57MV-JM88-66JC
GHSA-78X5-C8GW-8279

Affected Products

Fossbilling