PatchSiren cyber security CVE debrief
CVE-2026-53647 FOSSBilling CVE debrief
The FOSSBilling system, a free, open-source billing and client management solution, contains a security vulnerability in versions 0.5.3 through 0.7.2. Specifically, the Guest `serviceapikey/get_info` API endpoint is accessible without proper authentication. This allows any caller with a valid API key to retrieve all custom configuration parameters stored in the key's database record. These custom fields, populated by billing administrators, may contain sensitive business data such as pricing tiers, feature flags, rate limits, expiry overrides, or access scope information. The vulnerability was addressed in version 0.8.0 of FOSSBilling.
- Vendor
- FOSSBilling
- Product
- Unknown
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-07
- Original CVE updated
- 2026-07-07
- Advisory published
- 2026-07-07
- Advisory updated
- 2026-07-07
Who should care
Administrators and users of FOSSBilling versions 0.5.3 through 0.7.2 should be aware of this vulnerability. Security teams monitoring API logs for suspicious activity, especially related to `/api/guest/serviceapikey/get_info` calls, are also relevant. Additionally, anyone storing sensitive data in custom API key configuration fields should take immediate action.
Technical summary
In FOSSBilling versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endpoint lacks proper authentication controls. This endpoint allows retrieval of custom configuration parameters associated with a valid API key. The custom fields, set by administrators, can contain sensitive information. This issue was patched in version 0.8.0. Workarounds include avoiding storage of sensitive data in custom fields, monitoring API logs for unusual activity, and disabling the Serviceapikey module if not in use.
Defensive priority
Medium priority due to the CVSS score of 6.9 and potential for data exposure.
Recommended defensive actions
- Review and update FOSSBilling to version 0.8.0 or later
- Monitor API logs for suspicious calls to `/api/guest/serviceapikey/get_info`
- Avoid storing sensitive data in custom API key configuration fields
- Consider disabling the Serviceapikey module if not in active use
- Confirm whether affected FOSSBilling deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-07-07T00:16:34.263Z and last modified on 2026-07-07T15:16:48.137Z. The vulnerability details come from the CVE and NVD records, as well as a security advisory from GitHub.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-53647 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-53647
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-53647 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53647
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-737q-9gpr-6mpq
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.