Unauthenticated Access Vulnerability in FreePBX IP PBX System
CVE-2026-46376

9.3CRITICAL

Key Information:

Vendor

Freepbx

Vendor
CVE Published:
29 May 2026

What is CVE-2026-46376?

The vulnerability in FreePBX allows unauthenticated users to access the User Control Panel (UCP) using default credentials if not changed by the administrator during setup. While initial setup requires authenticated admin access to configure UCP generic templates, a lapse in securing these credentials may expose sensitive components to unauthorized users. This flaw affects versions 15.0.42 up to before 16.0.45 and 17.0.7 and has since been addressed in updated versions.

Affected Version(s)

security-reporting >= 15.0.42, < 16.0.45 < 15.0.42, 16.0.45

security-reporting >= 17.0.1, < 17.0.7 < 17.0.1, 17.0.7

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.