CVE-2026-33543 | FOSSBilling up to 0.7.x Unprotected Endpoint /api/guest/staff/create is_countable authentication bypass (GHSA-28mh-j262-q49w)

SecurityVulns

A vulnerability was found in FOSSBilling up to 0.7.x. It has been rated as critical. This impacts the function is_countable of the file /api/guest/staff/create of the component Unprotected Endpoint. Performing a manipulation results in authentication bypass using alternate channel.

This vulnerability is cataloged as CVE-2026-33543. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More