OAuth Private Key Vulnerability in FreePBX API Module
CVE-2025-55739
What is CVE-2025-55739?
The FreePBX API module has a vulnerability due to an identical OAuth private key being utilized across various installations of the same FreePBX RPM or DEB package. This flaw affects versions lower than 15.0.13, and from 16.0.2 to 16.0.14, and 17.0.1 and 17.0.2. An attacker with access to the common OAuth private key could forge JSON Web Tokens (JWT), potentially bypassing authentication measures to gain unauthorized access to REST and GraphQL APIs. Systems configured with the 'api' module enabled for remote inbound connections are particularly at risk. The issue has been addressed in later versions, specifically 15.0.13, 16.0.15, and 17.0.3.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
security-reporting < 15.0.13 < 15.0.13
security-reporting >= 16.0.2, < 16.0.15 < 16.0.2, 16.0.15
security-reporting >= 17.0.1, < 17.0.3 < 17.0.1, 17.0.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
