CVE-2026-54674
Received Received - Intake

Command Injection in FreePBX UCP

Vulnerability report for CVE-2026-54674, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

FreePBX is an open source IP PBX. Prior to versions 16.0.39 and 17.0.7, users authenticated via User Control Panel (UCP) are able to execute arbitrary commands on the PBX as the webserver user (typically asterisk) using specially crafted HTTP strings. Authenticated access to UCP is required. Note that this is often more common for less-privileged users to have UCP access vs. the Administrator Control Panel (ACP) access (which is usually FreePBX higher-level administrator accounts only). Insufficient sanitization of certain URL parameters utilized by UCP did not fully account for malicious strings in these fields. This could result in binaries being executed on the host server by carefully chaining commands. This issue has been patched in versions 16.0.39 and 17.0.7.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
freepbx freepbx to 16.0.39|end_excluding=17.0.7 (exc)
freepbx freepbx to 16.0.39 (exc)
freepbx freepbx to 17.0.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authenticated command injection vulnerability in FreePBX's User Control Panel (UCP). It allows users with UCP access to execute arbitrary commands on the PBX server as the webserver user (usually asterisk) by sending specially crafted HTTP strings. The issue stems from insufficient sanitization of URL parameters in UCP, enabling command chaining attacks.

Detection Guidance

Check FreePBX versions for affected releases (16.0.39 and below for FreePBX 16, 17.0.7 and below for FreePBX 17). Monitor UCP access logs for unusual HTTP requests with command-like parameters. Use network traffic analysis to detect suspicious outbound connections from the FreePBX server.

Impact Analysis

An attacker with UCP access could execute malicious commands on the server, potentially leading to unauthorized data access, system compromise, or disruption of PBX services. Since UCP access is often granted to less-privileged users, this increases the risk of exploitation by lower-level accounts.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for GDPR (data protection) and HIPAA (health information security). Unauthorized command execution may result in data breaches, unauthorized modifications, or system downtime, all of which are critical compliance violations.

Mitigation Strategies

Update FreePBX to versions 16.0.39 or 17.0.7 or later. Restrict UCP access to only trusted users. Disable unnecessary UCP modules. Implement additional security measures like Firewall, User Management, or MFA for UCP access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54674. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart