logo

FOSSBilling Flaw Lets Admin Attackers Abuse DI Container for SQL Access and RCE

ID: 5d50aebc-8f68-590a-a52f-54f17b0ebe91

STIX ID: report--5d50aebc-8f68-590a-a52f-54f17b0ebe91

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: Divya

...
...

A critical SSTI (CVE-2026-28496) in FOSSBilling's unsafe Twig template rendering allows arbitrary expression execution and exposure of the dependency-injection container, enabling database read/write, session hijacking, and remote code execution; active exploitation was observed within 24 hours (notably from 160.30.209.77), and users are urged to upgrade to 0.8.0 and perform incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.