logo

FreePBX Flaw Exposes User Portals to Unauthorized Access

ID: 403f35d8-2e17-5efd-aa1b-1b10edf72f53

STIX ID: report--403f35d8-2e17-5efd-aa1b-1b10edf72f53

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Lucas Martin

...
...

**FreePBX userman (CVE-2026-46376)** — A critical (CVSS v4.0 9.1) hard-coded credential vulnerability in the FreePBX userman module's UCP generic template can permit unauthenticated access to the User Control Panel if embedded sample passwords were not rotated. Affected FreePBX 16 (<16.0.45) and 17 (<17.0.7) have been patched (16.0.45, 17.0.7); administrators are advised to update immediately, restrict administrative access, deploy firewall controls, audit UCP sessions, and rotate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.