PT-2026-71884 · Freepbx · Freepbx

CVE-2026-73663

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreePBX versions 16.0.0 through 16.0.10 FreePBX versions prior to 17.0.4
Description The missedcall module fails to properly escape or use bound parameters when inserting the inbound Caller ID name from SIP From headers into the missedcalllog. This occurs within the agi-bin/missedcallnotify.php file. An unauthenticated caller can exploit this by sending crafted SIP headers when a monitored extension goes unanswered, allowing for SQL injection. This can lead to database corruption and the modification of administrator accounts to gain unauthorized remote access.
Recommendations Update to version 16.0.11. Update to version 17.0.4.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73663
GHSA-G27H-XF3Q-H3RM

Affected Products

Freepbx