Critical SSTI Vulnerability in FOSSBilling Exposes Databases to RCE Attacks

Critical SSTI Vulnerability in FOSSBilling Exposes Databases to RCE Attacks

First seen 26 Jun 2026, 16:54 UTC Gbhackersgithub.com 89% similarity 78.0
Share:

Article Content

Browse articles
ThreatCluster

A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, was disclosed on June 23, 2026. This flaw affects all versions up to 0.7.2 and allows attackers to exploit unsafe Twig template rendering, leading to full database compromise and remote code execution (RCE). The vulnerability can be exploited by both administrative users and unauthenticated attackers, particularly through features like email templates and the `string_render` API endpoint. The internal dependency injection (DI) container is also exposed, enabling attackers to perform arbitrary read/write operations on the database and hijack sessions. Threat intelligence indicates that exploitation attempts began within 24 hours of disclosure, highlighting the urgency of the situation. The flaw has a CVSS v4 score of 9.4, indicating a high impact on confidentiality, integrity, and availability. A patch was released in version 0.8.0, but the risk remains significant due to ongoing exploitation attempts.

Key Points: • CVE-2026-28496 exposes FOSSBilling to RCE and database compromise. • Exploitation attempts began within 24 hours of the vulnerability's disclosure. • The flaw affects all versions up to 0.7.2 and has been patched in version 0.8.0.

ThreatCluster AI

Timeline

2024-05-26
Public exploit for CVE-2025-8088 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-06-23
CVE-2026-28496 published
A critical SSTI vulnerability in FOSSBilling was disclosed, affecting all versions up to 0.7.2.
Gbhackers
2026-06-24
Active exploitation observed
Threat intelligence reported exploitation attempts began within 24 hours of the vulnerability's disclosure.
Gbhackers
2026-06-26
Patch released
FOSSBilling released version 0.8.0 to address the critical SSTI vulnerability.
Gbhackers

Community

Browse all →