CVE-2026-45562
Received Received - Intake

Command Injection in FreePBX Music on Hold Module

Vulnerability report for CVE-2026-45562, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw that allows authenticated attackers to execute arbitrary system commands with the privileges of the Asterisk service. Authentication with an existing FreePBX administrator account is required. The root cause lies in the fact that the module accepts a POST parameter that defines a custom Asterisk application, which is then stored in the database without any sanitization. Later, this data is written directly to the musiconhold_additional.conf configuration file without validation. Since Asterisk reads this configuration file and executes the specified application, an attacker can inject arbitrary commands that will be executed with Asterisk's permissions. This issue has been patched in versions 16.0.4 and 17.0.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
freepbx music_on_hold to 17.0.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in FreePBX's Music on Hold (MoH) module allows authenticated attackers with an administrator account to execute arbitrary system commands with Asterisk service privileges. The flaw occurs because the module accepts a POST parameter for a custom Asterisk application, stores it unsanitized in the database, and writes it directly to a configuration file without validation. Asterisk then executes the injected command.

Detection Guidance

Check FreePBX Music on Hold module version. Inspect musiconhold_additional.conf for suspicious Asterisk application commands. Review database entries for custom application parameters. Monitor Asterisk logs for unexpected command executions.

Impact Analysis

An attacker could gain control over the FreePBX system, execute malicious commands, steal data, or disrupt services. Since commands run with Asterisk's permissions, they could affect call handling, recordings, or other critical functions. The impact depends on the attacker's goals and system configuration.

Compliance Impact

This vulnerability could lead to unauthorized access, data breaches, or system compromise, violating compliance requirements for GDPR (data protection), HIPAA (health data security), and other regulations. Organizations may face legal penalties, reputational damage, and loss of trust due to non-compliance.

Mitigation Strategies

Update FreePBX Music on Hold module to versions 16.0.4 or 17.0.6 or later. Remove any suspicious entries from the database. Restrict access to FreePBX Administrator Control Panel. Block unauthorized network access to FreePBX interfaces.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-45562. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart