Gbhackers Critical SSTI Vulnerability in FOSSBilling Exposes Databases to RCE Attacks
Article Content
- •CVE-2026-28496 exposes FOSSBilling to RCE and database compromise.
- •Exploitation attempts began within 24 hours of the vulnerability's disclosure.
- •The flaw affects all versions up to 0.7.2 and has been patched in version 0.8.0.
A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, was disclosed on June 23, 2026. This flaw affects all versions up to 0.7.2 and allows attackers to exploit unsafe Twig template rendering, leading to full database compromise and remote code execution (RCE). The vulnerability can be exploited by both administrative users and unauthenticated attackers, particularly through features like email templates and the `string_render` API endpoint. The internal dependency injection (DI) container is also exposed, enabling attackers to perform arbitrary read/write operations on the database and hijack sessions. Threat intelligence indicates that exploitation attempts began within 24 hours of disclosure, highlighting the urgency of the situation. The flaw has a CVSS v4 score of 9.4, indicating a high impact on confidentiality, integrity, and availability. A patch was released in version 0.8.0, but the risk remains significant due to ongoing exploitation attempts.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track KuinaExtractor, FOSSBilling and CVE-2025-8088 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Path Traversal Vulnerability in WinRAR Exploited by RomCom Group CVE-2025-8088 is a path traversal vulnerability in WinRAR versions up to 7.12, allowing attackers to exploit alternate data streams (ADSes) in RAR files to extract malicious payloads to sensitive system locations. Exploitation began in the wild on July 18, 2025, with attackers linked to the Russia-aligned RomCom…
Critical Vulnerabilities in ClamAV Affecting Multiple File Parsers SUSE has issued important security advisories for ClamAV, addressing multiple denial of service vulnerabilities. The vulnerabilities, identified as CVE-2026-20213 through CVE-2026-20217 and CVE-2026-20337 through CVE-2026-20347, allow unauthenticated remote attackers to exploit flaws in various file format parsers…