PT-2026-71886 · Freepbx · Freepbx

CVE-2026-73665

·

Published

2026-08-13

·

Updated

2026-08-18

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FreePBX versions prior to 17.0.9
Description The UCP Node server on ports 8001 and 8003 utilizes io.use(checkAuth) in node/lib/server.js. However, Socket.IO version 4 only applies this middleware to the default namespace. This allows an unauthenticated client to connect to custom namespaces that do not consistently invoke the checkAuth() function in node/lib/auth.js. By sending crafted event values containing carriage-return or newline characters through the Asterisk Manager Interface (AMI) action path patched by node/lib/asterisk-manager-patch.js, an attacker can execute arbitrary commands as the asterisk service user.
Recommendations Update to version 17.0.9.

Fix

RCE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73665

Affected Products

Freepbx