PT-2026-99961 · Freepbx · Freepbx

·

CVE-2026-54710

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FreePBX versions prior to 16.0.40 FreePBX versions prior to 17.0.7
Description A remote code execution issue exists in the superfecta module due to the unsafe inclusion of arbitrary PHP files. Authenticated attackers with a known username can execute arbitrary PHP code on the server with web server user privileges. The flaw is located in the options and save options cases of the superfecta module's AJAX handler, where PHP files from the sources/ directory are dynamically included based on user input. This can be exploited when combined with arbitrary directory creation and file uploads that reveal full paths.
Recommendations Update to version 16.0.40 or later. Update to version 17.0.7 or later.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54710

Affected Products

Freepbx