Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-28496

FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE
Back to all
CVE

CVE-2026-28496

FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnerability in the template rendering system. Administrators with access to features that render Twig templates (email templates, mass mail campaigns, custom payment adapters, and the string_render API endpoint) can inject arbitrary Twig expressions, leading to information disclosure and remote code execution. The vulnerability exists because Twig templates are rendered without a sandbox, allowing access to the full Twig environment, API context, and the application's dependency injection container. Version 0.8.0 patches the issue. Some workarounds are available. Audit existing email templates for suspicious Twig expressions, rotate all admin and client API tokens, and/or block external access to /api/system/* at reverse proxy/WAF to mitigate chaining with GHSA-78x5-c8gw-8279.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.4
-
4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
-

Related Resources

No items found.

References

https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28496.json, https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-57mv-jm88-66jc, https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-78x5-c8gw-8279, https://nvd.nist.gov/vuln/detail/CVE-2026-28496, https://www.vulncheck.com/blog/fossbilling-auth-bypass-ssti-rce

Severity

0

CVSS Score
0
10

Basic Information

Base CVSS
0
EPSS Probability
0.17612%
EPSS Percentile
0.9691%
Introduced Version
0
Fix Available
3bd35f5b2921d8a26a403142ae0408f95e6463cc

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading