PT-2026-71883 · Freepbx · Freepbx
CVE-2026-73662
·
Published
2026-08-13
·
Updated
2026-08-13
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreePBX versions 17.0.1 through 17.0.6
Description
The Music on Hold module allows dangerous command-line options for
/usr/bin/mpg123 and other permitted players within the validateCustomConfiguration() function in Music.class.php. Because the applicationUsesDisallowedPlayerOption() function fails to reject these arguments, an authenticated administrator can use options to write files, open control channels, or create Asterisk call files, leading to arbitrary command execution as the asterisk service user.Recommendations
Update to version 17.0.7.
As a temporary mitigation, restrict administrative access to the Music on Hold module configuration.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freepbx