PT-2026-71886 · Freepbx · Freepbx
CVE-2026-73665
·
Published
2026-08-13
·
Updated
2026-08-18
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FreePBX versions prior to 17.0.9
Description
The UCP Node server on ports 8001 and 8003 utilizes
io.use(checkAuth) in node/lib/server.js. However, Socket.IO version 4 only applies this middleware to the default namespace. This allows an unauthenticated client to connect to custom namespaces that do not consistently invoke the checkAuth() function in node/lib/auth.js. By sending crafted event values containing carriage-return or newline characters through the Asterisk Manager Interface (AMI) action path patched by node/lib/asterisk-manager-patch.js, an attacker can execute arbitrary commands as the asterisk service user.Recommendations
Update to version 17.0.9.
Fix
RCE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freepbx