CVE-2026-54708
Received Received - Intake

Arbitrary Code Execution in FreePBX Backup Module

Vulnerability report for CVE-2026-54708, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX backup Module that allows authenticated attackers to execute arbitrary code on the server. Authentication with a known username that has sufficient access permissions and/or write access to backup files is required. This vulnerability is caused by improper path sanitization in the backup restore functionality, enabling attackers to upload malicious PHP files to the web root directory. This issue has been patched in versions 16.0.72 and 17.0.7.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
freepbx freepbx to 16.0.72|end_excluding=17.0.7 (exc)
freepbx backup_module to 16.0.72 (exc)
freepbx backup_module to 17.0.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-54708 is a critical vulnerability in the FreePBX backup module affecting versions before 16.0.72 and 17.0.7. It allows authenticated attackers with sufficient permissions to execute arbitrary code remotely by exploiting improper path sanitization in the backup restore functionality. This enables uploading malicious PHP files to the web root directory via path traversal.

Detection Guidance

Check FreePBX backup module version with: fwconsole ma list | grep backup. Look for versions below 16.0.72 or 17.0.7. Inspect web root directories for unexpected PHP files. Monitor for unauthorized file uploads or suspicious backup restore operations.

Impact Analysis

If exploited, this vulnerability allows attackers to execute arbitrary OS commands as the FreePBX service user (typically asterisk). This could lead to full system compromise, unauthorized data access, or further network infiltration. Attackers need authentication with sufficient permissions or write access to backup files.

Compliance Impact

This vulnerability could lead to high confidentiality and integrity loss, potentially violating GDPR (data protection) and HIPAA (health data privacy) requirements. Unauthorized code execution may result in data breaches, unauthorized access, or data tampering, triggering compliance violations and legal penalties.

Mitigation Strategies

Update FreePBX backup module to version 16.0.72 or 17.0.7 immediately. Restrict access to FreePBX Administrator Control Panel using User Management or MFA modules. Limit backup module access to trusted users only. Block hostile network access to ACP via Firewall module. Verify backup file authenticity using hashes before restoration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54708. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart