PT-2026-99962 · Freepbx · Freepbx

·

CVE-2026-75600

·

Published

2026-09-28

·

Updated

2026-10-01

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreePBX versions prior to 17.0.9
Description Authenticated users with access to the GraphQL api module interface can execute arbitrary shell commands. The issue occurs because the PBX API module documentation generator uses an authenticated host parameter to construct a shell command without proper validation or escaping. Although the system validates the OAuth access token, the lack of sanitization for the host variable allows command execution with the privileges of the FreePBX web/PBX service user, typically asterisk.
Recommendations Update to version 17.0.9.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75600

Affected Products

Freepbx