CVE-2026-54710
Received Received - Intake

Remote Code Execution in FreePBX Superfecta Module

Vulnerability report for CVE-2026-54710, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerability exists in the superfecta module due to unsafe inclusion of arbitrary PHP files, allowing authenticated attackers to execute arbitrary PHP code on the server with the privileges of the web server user. Authentication with a known username is required. The vulnerability is rooted in the options and save_options cases in the Superfecta module's AJAX handler. The code dynamically includes PHP files from the sources/ directory based on user-supplied input. This allows an attacker to execute arbitrary code when combined with arbitrary directory creation (e.g., via the backup module) and file uploads that reveal full paths (e.g., via the soundlang module). This issue has been patched in versions 16.0.40 and 17.0.7.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
freepbx freepbx to 17.0.7 (exc)
freepbx superfecta to 17.0.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-54710 is a critical remote code execution (RCE) vulnerability in FreePBX's Superfecta module affecting versions 16 and 17. It allows authenticated attackers to execute arbitrary PHP code on the server with web server user privileges by exploiting unsafe file inclusion in the AJAX handler. The flaw stems from dynamic inclusion of PHP files based on user input.

Detection Guidance

Check FreePBX module versions for Superfecta. Use commands like 'fwconsole ma list' to verify if Superfecta is below 16.0.40 or 17.0.7. Inspect web server logs for unusual PHP file inclusions or unauthorized access attempts to the Superfecta AJAX handler.

Impact Analysis

This vulnerability allows attackers with valid credentials to run malicious code on your FreePBX server, potentially leading to full system compromise. Attackers could steal data, install malware, or disrupt phone services. The impact depends on server configuration and network access.

Compliance Impact

This RCE vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations may face compliance violations, fines, or legal consequences if exploited.

Mitigation Strategies

Update the Superfecta module to versions 16.0.40 or 17.0.7 immediately. Restrict access to the FreePBX Administrator Control Panel using modules like User Management, SysAdmin VPN, MFA, or SAML to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54710. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart