CRITICAL🇵🇱 Wersja polska

CVE-2026-46376

CVSS 9.3v4.0pub. 2026-05-29upd. 2026-07-21

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not immediately changed by the Administrator who enabled UCP. Authenticated access to ACP is required for the initial setup of UCP generic templates, but after that, without further steps by the admin, unauthenticated users may be able to gain access. This vulnerability is fixed in 16.0.45 and 17.0.7.

🤖 AI Analysis
How it works

During the configuration of general UCP templates, the system uses predefined, hard-coded credentials (CWE-798). Although access to the ACP panel is required from an administrator to initially configure the templates, after completion, without additional actions by the administrator, these credentials remain active. An attacker without any privileges can exploit these default, unchanged credentials to log in to UCP over the network without any authentication.

Impact

An attacker can gain unauthorized access to the User Control Panel (UCP) of the FreePBX system, which may result in breach of confidentiality and integrity of data available in this panel.

Mitigation & patch

FreePBX should be updated to version 16.0.45 or 17.0.7, in which the vulnerability has been fixed. Until the update is applied, administrators should immediately change the default credentials in UCP templates or disable the UCP feature if it is not required.

Who is affected

FreePBX in versions from 15.0.42 to before 16.0.45 and in versions before 17.0.7

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sangoma Freepbx

    APP
    Sangoma
    < 16.0.4517.0 – 17.0.7 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-57819CRITICAL10.0⚠ KEVPL ✓same product

Krytyczna podatność RCE i SQL injection w Sangoma FreePBX (bez uwierzytelnienia)

CVE-2019-19006CRITICAL9.8⚠ KEVPL ✓same product

Obejście uwierzytelnienia administratora w Sangoma FreePBX

CVE-2025-66039CRITICAL9.3PL ✓same product

FreePBX Endpoint Manager — pominięcie uwierzytelnienia (Auth Bypass)

CVE-2021-45461CRITICAL9.8PL ✓same product

RCE w FreePBX przez moduł Rest Phone Apps (restapps)

CVE-2020-10666CRITICAL9.8PL ✓same product

RCE w module restapps dla Sangoma FreePBX i PBXact