logo

VoIP Backbone Exposed: Critical FreePBX Flaw (CVE-2026-46376) Allows Unauthenticated Access to User Portals

ID: e9f58ce9-2222-5596-8c08-3716069893fa

STIX ID: report--e9f58ce9-2222-5596-8c08-3716069893fa

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Ddos

...
...

FreePBX fixed a critical vulnerability (CVE-2026-46376, CVSS 9.1) in its User Control Panel where static, hard-coded template credentials used during generic UCP template setup could be abused by unauthenticated attackers to gain UCP access; affected FreePBX 16 versions prior to 16.0.45 and 17 versions prior to 17.0.7 should apply updates and follow recommended mitigations (randomized template passwords, restrict ACP/UCP access, firewall/segmentation, MFA/SAML).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.