FreePBX Vulnerabilities and Affected Products
Vulnerabilities associated with api.
Products
Clear product- security-reporting9 vulnerabilities
- framework5 vulnerabilities
- endpoint4 vulnerabilities
- api3 vulnerabilities
- endpointman2 vulnerabilities
- FreePBX2 vulnerabilities
- tts2 vulnerabilities
- arimanager1 vulnerability
- backup1 vulnerability
- cdr1 vulnerability
- contactmanager1 vulnerability
- core1 vulnerability
- endpoint_manager1 vulnerability
- filestore1 vulnerability
- FreePBX Framework1 vulnerability
- missedcall1 vulnerability
- music1 vulnerability
- restapps1 vulnerability
- ucp1 vulnerability
- voicemail1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-40520HIGH | FreePBX api module Command Injection via GraphQLFreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation input fields are passed directly to shell_exec() without sanitization or escaping. An authenticated user with a valid bearer token can send a GraphQL moduleOperations mutation with backtick-wrapped commands in the module field to execute arbitrary commands on the underlying host as the web server user. CWE-78Apr 21, 2026 | CVSS8.6v4.0 | EPSS1.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional ScopesFreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API) is vulnerable to privilege escalation by authenticated users with REST/GraphQL API access. This vulnerability allows an attacker to forge a valid JWT with full access to the REST and GraphQL APIs on a FreePBX that they've already connected to, possibly as a lower privileged user. The JWT is signed using the api-oauth.key private key. An attacker can … CWE-270Feb 12, 2026 | CVSS2.0v4.0 | EPSS0.296% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-55739MEDIUM | api: Shared OAuth Signing Key Between Different Instancesapi is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through 16.0.14, 17.0.1 and 17.0.2, there is an identical OAuth private key used across multiple systems that installed the same FreePBX RPM or DEB package. An attacker with access to the shared OAuth private key could forge JWT tokens, bypass authentication, and potentially gain full access to both REST and GraphQL APIs. Systems with the "api" module enable… | CVSS5.1v4.0 | EPSS0.41% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |