AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-28496.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSUnscoredNo severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSAwaiting NVD dataModified Jun 22, 2026

Disclosure summary

VulnCheck's Initial Access Intelligence team analyzes a chained auth bypass and Twig SSTI in FOSSBilling that yields pre-authentication remote code execution against default instal

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

VulnCheck Blog · RSS-9636c568e50e698a97bc03a5b02984a27b8

Open original source · Updated Jun 22, 2026

CVE-2026-28496 - FOSSBilling Auth Bypass and Twig SSTI to Unauthenticated RCE

CVE mention in publisher metadata; check the original affected versions.

Original records & references

PUBLISHED 2026-06-22T20:00:00-04:00
MODIFIED 2026-06-22T20:00:00-04:00
INGESTED 2026-10-08T12:25:05-04:00