AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-53644

HIGH · CVSS 8.6 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

FOSSBilling versions 0.5.3 to 0.7.2 are vulnerable, allowing authenticated clients to read and reset API key service secrets for non-active orders due to inadequate order-state validation in specific API endpoints. This flaw could lead to unauthorized access to sensitive API keys, potentially compromising client data and billing processes. Organizations using affected versions should prioritize upgrading to version 0.8.0 or implementing available workarounds to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-53644
Severity
HIGH
CVSS
8.6
EPSS
0.25%

Original NVD Description

FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticated clients to both read and reset API key service secrets for orders that are no longer in an `active` state (e.g., `suspended`, `canceled`). The root cause is missing order-state validation in two client API endpoints, despite an `isActive()` helper already existing in the `Serviceapikey` module and the frontend UI correctly gating access on `order.status == 'active'`. Version 0.8.0 contains a fix. Some workarounds are available. If the `Serviceapikey` module is not needed, uninstall it to remove the affected endpoints. One may also use a reverse proxy or WAF to restrict access to `/api/client/order/service` and `/api/client/serviceapikey/reset` based on application-level order-state logic.