AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-73660

HIGH · CVSS 7.5 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The FreePBX Text-To-Speech module is vulnerable to arbitrary command execution due to improper handling of HTML-encoded input by authenticated administrators, which can lead to execution of malicious commands as the asterisk service user. This high-severity vulnerability affects versions prior to 16.0.6 and 17.0.5.4, and organizations using these versions should prioritize upgrading to mitigate potential exploitation risks. System administrators and security teams managing FreePBX installations should take immediate action to patch their systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73660
Severity
HIGH
CVSS
7.5
EPSS
0.44%

Original NVD Description

FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that is HTML-encoded for storage, decoded during dialplan generation, passed as an AGI argument, and used to build filenames inside agi-bin/propolys-tts.agi. The TTS destination name reaches a raw shell-command execution path, allowing arbitrary operating-system command execution as the asterisk service user. This issue is fixed in versions 16.0.6 and 17.0.5.4.