Critical SSTI Vulnerability in FOSSBilling Exposes Databases to RCE Attacks
ID: 01ac258b-02f5-5ba6-8c20-11f4239e9bea
STIX ID: report--01ac258b-02f5-5ba6-8c20-11f4239e9bea
Feed Name: ThreatCluster
**Executive Summary:** A critical SSTI (CVE-2026-28496) in FOSSBilling (affecting all versions up to 0.7.2) allows unauthenticated and administrative attackers to perform remote code execution and full database compromise via unsafe Twig template rendering (including email templates and the string_render API); CVSS v4 score is 9.4. A patch is included in version 0.8.0, but exploitation attempts began within 24 hours of disclosure and continue, making immediate patching and mitigation urgent.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
