FreePBX Flaw Exposes User Portals to Unauthorized Access
ID: 403f35d8-2e17-5efd-aa1b-1b10edf72f53
STIX ID: report--403f35d8-2e17-5efd-aa1b-1b10edf72f53
Feed Name: Cyber Press
**FreePBX userman (CVE-2026-46376)** — A critical (CVSS v4.0 9.1) hard-coded credential vulnerability in the FreePBX userman module's UCP generic template can permit unauthenticated access to the User Control Panel if embedded sample passwords were not rotated. Affected FreePBX 16 (<16.0.45) and 17 (<17.0.7) have been patched (16.0.45, 17.0.7); administrators are advised to update immediately, restrict administrative access, deploy firewall controls, audit UCP sessions, and rotate credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
