CVE-2026-42331 | FOSSBilling up to 0.5.5 Guest API gateway_id improper authorization (EUVD-2026-41947)
A vulnerability was found in FOSSBilling 0.5.0/0.5.1/0.5.3/0.5.4/0.5.5. It has been rated as problematic. The impacted element is an unknown function of the component Guest API. This manipulation of the argument gateway_id causes improper authorization.
This vulnerability is tracked as CVE-2026-42331. The attack is possible to be carried out remotely. No exploit exists.