Threat intelligence dashboard
CVE-2026-75600high

FreePBX: Authenticated API generatedocs Host Command Injection

FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL api module interface of FreePBX are able to execute arbitrary shell commands. Authenticated access to the api module is required. The PBX API module's documentation generator accepts an authenticated host parameter and uses it to build a shell command. The code path validates the generated OAuth access token before execution, but it does not validate or escape host. Compromise results in authenticated arbitrary shell command execution as the FreePBX web/PBX service user (typically asterisk.). This issue has been patched in version 17.0.9.

Risk score

8.6

CVSS 4.0

Vendor
FreePBX
Product
security-reporting
CWE
CWE-78
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

security-reporting

FreePBX

Version / rangeStatusType
< 17.0.9affected—

Technical metrics

8.6

CVSS 4.0

Severity
high
Source
GitHub_M
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N