Filtered by vendor Killbill
Subscriptions
Filtered by product Killbill
Subscriptions
Total
1 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-85213 | 1 Killbill | 1 Killbill | 2026-09-03 | 7.6 High |
| Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation. | ||||
Page 1 of 1.