logo

Critical FreePBX Flaws Let Unauthenticated Attackers Execute Code and Take Over Administrator Accounts

ID: 87ad4c7c-9918-5d68-9cd0-075298b8dd68

STIX ID: report--87ad4c7c-9918-5d68-9cd0-075298b8dd68

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Divya

...
...

Two critical vulnerabilities in FreePBX (GHSA-37j8-fhxx-9vhp and GHSA-g27h-xf3q-h3rm, CVSS 9.3) affect versions 16 and 17: an unauthenticated RCE in the UCP module via socket.io namespace authentication bypass enabling AMI command injection, and an unauthenticated SQL injection in the missedcall module that can allow administrator account takeover; Sangoma released patches (UCP 17.0.9, missedcall 16.0.11 and 17.0.6) and administrators are urged to patch immediately, restrict access to UCP/admin interfaces, and filter/sanitize SIP traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.