PT-2026-71883 · Freepbx · Freepbx

CVE-2026-73662

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreePBX versions 17.0.1 through 17.0.6
Description The Music on Hold module allows dangerous command-line options for /usr/bin/mpg123 and other permitted players within the validateCustomConfiguration() function in Music.class.php. Because the applicationUsesDisallowedPlayerOption() function fails to reject these arguments, an authenticated administrator can use options to write files, open control channels, or create Asterisk call files, leading to arbitrary command execution as the asterisk service user.
Recommendations Update to version 17.0.7. As a temporary mitigation, restrict administrative access to the Music on Hold module configuration.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73662
GHSA-P97W-RQ48-P8Q2

Affected Products

Freepbx