PT-2026-71885 · Freepbx · Freepbx
CVE-2026-73664
·
Published
2026-08-13
·
Updated
2026-08-13
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FreePBX versions 17.0.5.34 through 17.0.10
Description
The
publicKeySave AJAX endpoint in Backup.class.php allows an authenticated administrator to provide an SSH public key that is appended to the /home/asterisk/.ssh/authorized keys file for the asterisk system user. This process fails to reliably enforce restrictions on the source and the commands allowed for backups. Consequently, this can grant persistent shell access, enabling the execution of arbitrary commands, access to call data, modification of system files, and service disruption.Recommendations
Update to version 17.0.11.
Fix
Improper Access Control
Improper Privilege Management
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freepbx