logo

FreePBX Vulnerability Allow Attackers to Gain Access to User Portals

ID: f8315811-9436-550d-a5f1-d1154af98fbf

STIX ID: report--f8315811-9436-550d-a5f1-d1154af98fbf

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Abinaya

...
...

A critical vulnerability (CVE-2026-46376) in FreePBX's User Control Panel stems from hard-coded sample credentials in the userman module, allowing unauthenticated remote access to UCP in FreePBX versions before 16.0.45 and 17.0.7; it carries a CVSS v4 base score of 9.1 and administrators are urged to apply vendor patches and harden deployments immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.