PT-2026-71885 · Freepbx · Freepbx

CVE-2026-73664

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FreePBX versions 17.0.5.34 through 17.0.10
Description The publicKeySave AJAX endpoint in Backup.class.php allows an authenticated administrator to provide an SSH public key that is appended to the /home/asterisk/.ssh/authorized keys file for the asterisk system user. This process fails to reliably enforce restrictions on the source and the commands allowed for backups. Consequently, this can grant persistent shell access, enabling the execution of arbitrary commands, access to call data, modification of system files, and service disruption.
Recommendations Update to version 17.0.11.

Fix

Improper Access Control

Improper Privilege Management

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73664

Affected Products

Freepbx