ProductThird-party advisory
https://github.com/FreePBX/framework CVE-2026-72578
HIGH
FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher
Record summary
CVE-2026-72578 has a selected CVSS score of 8.8 (high).
Description
A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actions on behalf of an authenticated administrator.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FreePBX FrameworkBrowse FreePBX / FreePBX FrameworkDefault status: unknown | CVE List | 17.0 | affected |
References
3Vulnerable FileTechnical description
https://github.com/FreePBX/framework/blob/release/17.0/amp_conf/htdocs/admin/libraries/BMO/Ajax.class.php nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-72578