A vulnerability in FOSSBilling, the open-source billing and client management system, tracked as CVE-2026-43926, exposes password reset tokens through the confirmation endpoint at /client/reset-password-confirm/:hash. Versions prior to 0.8.0 are affected.
What Is the Vulnerability?
CVE-2026-43926 is an information disclosure vulnerability in the password reset confirmation endpoint. The /client/reset-password-confirm/:hash endpoint leaks the password reset hash, allowing an attacker who can observe or intercept traffic to this endpoint to capture valid password reset tokens and take over user accounts.
- CVSS v3.1 Score: 7.5 (High)
Which Versions Are Affected?
- FOSSBilling: all versions prior to 0.8.0
What Is the Fix?
Update FOSSBilling to version 0.8.0 or later.
References
This advisory is covered in the broader Vulnerability Intelligence Report — June 4, 2026.
