CVE-2026-75600
Received Received - Intake

Authenticated Command Injection in FreePBX

Vulnerability report for CVE-2026-75600, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL api module interface of FreePBX are able to execute arbitrary shell commands. Authenticated access to the api module is required. The PBX API module's documentation generator accepts an authenticated host parameter and uses it to build a shell command. The code path validates the generated OAuth access token before execution, but it does not validate or escape host. Compromise results in authenticated arbitrary shell command execution as the FreePBX web/PBX service user (typically asterisk.). This issue has been patched in version 17.0.9.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
freepbx freepbx to 17.0.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows authenticated users with access to FreePBX's GraphQL API module to execute arbitrary shell commands. The issue occurs because the API's documentation generator accepts an authenticated host parameter and uses it to build a shell command without proper validation or escaping. This leads to command injection, allowing attackers to run commands as the FreePBX web/PBX service user (typically asterisk).

Detection Guidance

To detect this vulnerability, check FreePBX API module version with: fwconsole module list | grep api. If version is below 17.0.9, it is vulnerable. Review API access logs for unusual host parameters or shell command patterns in requests.

Impact Analysis

If exploited, this vulnerability could allow attackers to take full control of the FreePBX system, execute malicious commands, steal data, or disrupt services. Since it requires authenticated access, attackers must first gain valid credentials or exploit another vulnerability to access the API.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and access controls. Organizations using affected FreePBX versions may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Immediately update FreePBX API module to version 17.0.9 or later using fwconsole ma upgrade api. Restrict API access to authorized users only and block external network access to the API endpoint. Monitor for suspicious activity in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75600. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart