ZeroHour

CVE-2026-85213

niche

Missing Authorization in Kill Bill Admin APIs Lets Low-Privilege Users Disrupt Billing Server

CVSS 4.0
7.2 high
EPSS
<1%p12
Published
()
Modified
AI analysis

Kill Bill through 0.24.21 does not enforce its permission annotations on several AdminResource endpoints, including getQueueEntries, invalidatesCache, and putOutOfRotation, creating a missing-authorization flaw (CWE-862). An attacker needs only any authenticated API account that holds the minimal account:read permission and network access to the admin API; no user interaction is required. Such a caller can read internal queue data, flush server caches, and put the host out of rotation, effectively disabling the billing server (CVSS 4.0: 7.2 High, with high availability impact on the vulnerable component). Deployments running Kill Bill 0.24.21 or earlier that expose the admin endpoints to low-privilege API keys are affected. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns a 0.2% probability of exploitation within 30 days, so no active exploitation is known.

What to do: Upgrade Kill Bill to a release newer than 0.24.21 as soon as a patched version is published, and monitor the vendor's advisory for the fixed version. In the interim, restrict network access to the AdminResource endpoints (getQueueEntries, invalidatesCache, putOutOfRotation) to trusted administrative callers, and audit API keys and users that hold the account:read permission to ensure low-privilege accounts cannot reach the admin API.

Affected
Kill Billthrough 0.24.21 (all versions up to and including 0.24.21)
Estimated exposure
nicheNo basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.