S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 24, 2026

CVE-2026-28496 Scanner

CVE-2026-28496 Scanner - Server-Side Template Injection (SSTI) vulnerability in FOSSBilling

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-28496
9.4
CVSScritical
Exploitable remotely over the internet · requires high privileges.

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnerability in the template rendering system. Administrators with access to features that render Twig templates (email templates, mass mail campaigns, custom payment adapters, and the `string_render` API endpoint) can inject arbitrary Twig expressions, leading to information disclosure and remote code execution. The vulnerability exists because Twig templates are rendered without a sandbox, allowing access to the full Twig environment, API context, and the application's dependency injection container. Version 0.8.0 patches the issue. Some workarounds are available. Audit existing email templates for suspicious Twig expressions, rotate all admin and client API tokens, and/or block external access to /api/system/* at reverse proxy/WAF to mitigate chaining with GHSA-78x5-c8gw-8279.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
FOSSBillingby FOSSBilling
< 0.8.0
Updated Sep 9, 2026View on NVD →
Detail

FOSSBilling is a widely used open-source billing and client management solution for hosting providers. It is typically utilized by administrators and developers who require a streamlined system for billing and client management. FOSSBilling's integration capabilities make it a popular choice for businesses seeking an efficient, customizable billing system. The software supports extensive third-party plugins, enhancing its functionality across various business environments. Many hosting companies rely on FOSSBilling for its robust features and adaptability to diverse billing needs. Its community-driven development ensures ongoing updates and improvements that meet user needs.

The Server Side Template Injection (SSTI) vulnerability allows attackers to inject and execute arbitrary code through templates. This vulnerability arises when the software fails to properly validate and sanitize untrusted input. Attackers can leverage SSTI vulnerabilities to execute server-side code, accessing sensitive information or performing unauthorized actions. In FOSSBilling, the vulnerability is associated with the template rendering system, which handles various administrative tasks. The unchecked rendering process can enable unauthorized access to critical systems and data. Proper handling and sanitization of inputs are essential to prevent such vulnerabilities.

Technically, this SSTI vulnerability affects FOSSBilling's template rendering system, specifically with the rendering of Twig templates. It occurs due to the absence of a sandbox during the rendering process, allowing full access to the Twig environment. This lack of restriction permits administrators to inject arbitrary expressions, compromising system security. Key vulnerable endpoints include email templates, mass mail campaigns, and custom payment adapters. Moreover, the string_render API endpoint is particularly vulnerable to crafted template injections. The unrestricted use of dependency injection containers heightens the potential impact of the vulnerability.

Exploiting this vulnerability can have dire consequences, including the potential compromise of the entire system. Attackers could execute arbitrary code, leading to unauthorized access and control over the application's functions. Sensitive information, including client data and system configurations, could be disclosed, impacting business operations and client trust. Moreover, the system could become a launchpad for further attacks against other network-connected resources. The exploitation of this vulnerability can also result in reputational damage and financial loss for affected organizations.

REFERENCES

Solution Advice
  • Update FOSSBilling to version 0.8.0 or later to address the vulnerability.
  • Implement a secure sandbox environment for rendering templates to prevent unauthorized code execution.
  • Regularly audit and sanitize inputs within all template rendering functions.
  • Apply principle of least privilege to restrict access to critical administrative features.
  • Regularly monitor systems for unusual activity that may indicate exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.