Remote Code Execution Vulnerability in FreePBX Product by Sangoma
CVE-2026-54675

8.7HIGH

Key Information:

Vendor

Freepbx

Vendor
CVE Published:
28 September 2026

What is CVE-2026-54675?

FreePBX, an open-source IP PBX software, contains an issue in the sound language upload and conversion feature prior to versions 16.0.10 and 17.0.5. This vulnerability allows an authenticated attacker with a known username to perform arbitrary file writes due to inadequate path sanitization. As a result, a path traversal attack can be executed, leading to the placement of malicious PHP files in the server's root directory, which could enable remote code execution. The issue has been addressed in subsequent versions, providing necessary security improvements.

Affected Version(s)

security-reporting < 16.0.10 < 16.0.10

security-reporting < 17.0.5 < 17.0.5

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.