CVE-2026-85213
Kill Bill through 0.24.21 Missing Authorization on AdminResource Endpoints
CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
0th
Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation.
| CWE | CWE-862 |
| Vendor | killbill |
| Product | killbill |
| Published | Sep 3, 2026 |
| Last Updated | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for killbill killbill
Be the first to know when new high vulnerabilities affecting killbill killbill are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High
Affected Versions
killbill / killbill
0 โค 0.24.21
References
github.com: https://github.com/killbill/killbill/issues/2251 github.com: https://github.com/killbill/killbill github.com: https://github.com/killbill/killbill/blob/killbill-0.24.21/jaxrs/src/main/java/org/killbill/billing/jaxrs/resources/AdminResource.java vulncheck.com: https://www.vulncheck.com/advisories/kill-bill-through-0.24.21-missing-authorization-on-adminresource-endpoints
Credits
๐ George Chen