OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-54708

HIGH · CVSS 8.6 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The FreePBX backup module prior to versions 16.0.72 and 17.0.7 is vulnerable to arbitrary code execution due to improper path sanitization, allowing authenticated users with sufficient permissions to upload malicious PHP files to the server's web root directory. This poses a significant risk as it can lead to full system compromise. Organizations using affected versions should prioritize patching to mitigate potential exploitation by attackers.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54708
Severity
HIGH
CVSS
8.6
EPSS
0.45%

Original NVD Description

FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX backup Module that allows authenticated attackers to execute arbitrary code on the server. Authentication with a known username that has sufficient access permissions and/or write access to backup files is required. This vulnerability is caused by improper path sanitization in the backup restore functionality, enabling attackers to upload malicious PHP files to the web root directory. This issue has been patched in versions 16.0.72 and 17.0.7.