PT-2026-47852 · Unknown · Freeswitch

CVE-2026-49848

·

Published

2026-06-09

·

Updated

2026-06-09

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions FreeSWITCH versions prior to 1.11.1
Description In the mod verto module, the check auth userauth branch writes request-supplied userVariables into the connection state before the supplied password is compared. Because these writes are append-only and the connection remains open after a failed password comparison, values provided during unsuccessful login attempts persist on the same WebSocket. These variables are then carried over into a subsequent successful login on that same connection.
Recommendations Update to version 1.11.1.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49848
GHSA-J38X-XM7F-9P2F

Affected Products

Freeswitch