No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 28 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freepbx
Freepbx security-reporting |
|
| Vendors & Products |
Freepbx
Freepbx security-reporting |
|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreePBX is an open source IP PBX. Prior to versions 16.0.39 and 17.0.7, users authenticated via User Control Panel (UCP) are able to execute arbitrary commands on the PBX as the webserver user (typically asterisk) using specially crafted HTTP strings. Authenticated access to UCP is required. Note that this is often more common for less-privileged users to have UCP access vs. the Administrator Control Panel (ACP) access (which is usually FreePBX higher-level administrator accounts only). Insufficient sanitization of certain URL parameters utilized by UCP did not fully account for malicious strings in these fields. This could result in binaries being executed on the host server by carefully chaining commands. This issue has been patched in versions 16.0.39 and 17.0.7. | |
| Title | Authenticated Command Injection in FreePBX UCP Interface | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-28T18:43:23.063Z
Reserved: 2026-06-15T22:53:58.560Z
Link: CVE-2026-54674
Updated: 2026-09-28T18:43:08.488Z
Status : Received
Published: 2026-09-28T18:17:22.560
Modified: 2026-09-28T19:16:49.493
Link: CVE-2026-54674
No data.
OpenCVE Enrichment
Updated: 2026-09-28T19:15:05Z