OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-54674

HIGH · CVSS 8.6 EPSS 0.60% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

FreePBX versions prior to 16.0.39 and 17.0.7 are vulnerable due to insufficient sanitization of URL parameters in the User Control Panel (UCP), allowing authenticated users to execute arbitrary commands on the server as the webserver user. This vulnerability poses a significant risk, as it can lead to unauthorized command execution and potential system compromise. Organizations using affected versions should prioritize updating to the patched releases, especially those with less-privileged users accessing UCP.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54674
Severity
HIGH
CVSS
8.6
EPSS
0.60%

Original NVD Description

FreePBX is an open source IP PBX. Prior to versions 16.0.39 and 17.0.7, users authenticated via User Control Panel (UCP) are able to execute arbitrary commands on the PBX as the webserver user (typically asterisk) using specially crafted HTTP strings. Authenticated access to UCP is required. Note that this is often more common for less-privileged users to have UCP access vs. the Administrator Control Panel (ACP) access (which is usually FreePBX higher-level administrator accounts only). Insufficient sanitization of certain URL parameters utilized by UCP did not fully account for malicious strings in these fields. This could result in binaries being executed on the host server by carefully chaining commands. This issue has been patched in versions 16.0.39 and 17.0.7.