github.comConfirmation
https://github.com/FreePBX/security-reporting/security/advisories/GHSA-p9fq-fmpw-2h9x CVE-2026-44238
HIGH
FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports
Record summary
CVE-2026-44238 has a selected CVSS score of 8.5 (high).
Description
FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST parameters. Authentication with a FreePBX Administration Control Panel account that has CDR section access is required. Full administrator privileges are not needed. This vulnerability is fixed in 16.0.50 and 17.0.11.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 29, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
security-reportingBrowse FreePBX / security-reporting | CVE List | < 16.0.50 | affected |
| >= 17.0.1, < 17.0.11 | affected |