CVE-2026-85213
nicheMissing Authorization in Kill Bill Admin APIs Lets Low-Privilege Users Disrupt Billing Server
Kill Bill through 0.24.21 does not enforce its permission annotations on several AdminResource endpoints, including getQueueEntries, invalidatesCache, and putOutOfRotation, creating a missing-authorization flaw (CWE-862). An attacker needs only any authenticated API account that holds the minimal account:read permission and network access to the admin API; no user interaction is required. Such a caller can read internal queue data, flush server caches, and put the host out of rotation, effectively disabling the billing server (CVSS 4.0: 7.2 High, with high availability impact on the vulnerable component). Deployments running Kill Bill 0.24.21 or earlier that expose the admin endpoints to low-privilege API keys are affected. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns a 0.2% probability of exploitation within 30 days, so no active exploitation is known.
What to do: Upgrade Kill Bill to a release newer than 0.24.21 as soon as a patched version is published, and monitor the vendor's advisory for the fixed version. In the interim, restrict network access to the AdminResource endpoints (getQueueEntries, invalidatesCache, putOutOfRotation) to trusted administrative callers, and audit API keys and users that hold the account:read permission to ensure low-privilege accounts cannot reach the admin API.
| Kill Bill | through 0.24.21 (all versions up to and including 0.24.21) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.