OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-45562

HIGH · CVSS 7.7 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Music on Hold (MoH) module in FreePBX versions prior to 16.0.4 and 17.0.6 is vulnerable to command injection, allowing authenticated attackers with administrator access to execute arbitrary system commands with Asterisk's privileges. This flaw arises from the lack of input sanitization for a POST parameter, which is stored in the database and directly written to a configuration file executed by Asterisk. Organizations using affected versions of FreePBX should prioritize upgrading to the patched versions to mitigate the risk of unauthorized command execution.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-45562
Severity
HIGH
CVSS
7.7
EPSS
0.30%

Original NVD Description

FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw that allows authenticated attackers to execute arbitrary system commands with the privileges of the Asterisk service. Authentication with an existing FreePBX administrator account is required. The root cause lies in the fact that the module accepts a POST parameter that defines a custom Asterisk application, which is then stored in the database without any sanitization. Later, this data is written directly to the musiconhold_additional.conf configuration file without validation. Since Asterisk reads this configuration file and executes the specified application, an attacker can inject arbitrary commands that will be executed with Asterisk's permissions. This issue has been patched in versions 16.0.4 and 17.0.6.