FreePBX Vulnerabilities and Affected Products
Vulnerabilities associated with framework.
Products
Clear product- security-reporting9 vulnerabilities
- framework5 vulnerabilities
- endpoint4 vulnerabilities
- api3 vulnerabilities
- endpointman2 vulnerabilities
- FreePBX2 vulnerabilities
- tts2 vulnerabilities
- arimanager1 vulnerability
- backup1 vulnerability
- cdr1 vulnerability
- contactmanager1 vulnerability
- core1 vulnerability
- endpoint_manager1 vulnerability
- filestore1 vulnerability
- FreePBX Framework1 vulnerability
- missedcall1 vulnerability
- music1 vulnerability
- restapps1 vulnerability
- ucp1 vulnerability
- voicemail1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-73661HIGH | FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted BackupFreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or write access to backup files can thereby disable FreePBX authentication during restoration, bypassing the user-interface removal of AUTHTYPE=none. This issue is fixed in versions 16.0… CWE-15Aug 13, 2026 | CVSS8.6v4.0 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67722MEDIUM | Authenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalationFreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script `amportal`. In the deprecated `amportal` utility, the lookup for the `freepbx_engine` file occurs in `/etc/asterisk/` directories. Typically, these are configured by FreePBX as writable by the **asterisk** user and any members of the **asterisk** group. … CWE-426Dec 16, 2025 | CVSS5.7v4.0 | EPSS0.125% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66039CRITICAL | FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth HeaderFreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23. CWE-287Dec 9, 2025 | CVSS9.3v4.0 | EPSS3.31% | PoCs6 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59056MEDIUM | FreePBX vulnerable to unauthenticated Denial of ServiceFreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web interface can cause the uninstall function to be triggered for certain modules. This function drops the module's database tables, which is where most modules store their configuration. This vulnerability is fixed in 15.0.38, 16.0.41, and 17.0.21. CWE-22Sep 15, 2025 | CVSS6.6v4.0 | EPSS0.434% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-55211MEDIUM | FreePBX Post-Authenticated Command InjectionFreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages of the framework module. This vulnerability is fixed in 17.0.21. CWE-78Sep 15, 2025 | CVSS6.3v4.0 | EPSS0.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |