Remote Code Execution Vulnerability in FreePBX Product by Sangoma
CVE-2026-54675
8.7HIGH
What is CVE-2026-54675?
FreePBX, an open-source IP PBX software, contains an issue in the sound language upload and conversion feature prior to versions 16.0.10 and 17.0.5. This vulnerability allows an authenticated attacker with a known username to perform arbitrary file writes due to inadequate path sanitization. As a result, a path traversal attack can be executed, leading to the placement of malicious PHP files in the server's root directory, which could enable remote code execution. The issue has been addressed in subsequent versions, providing necessary security improvements.
Affected Version(s)
security-reporting < 16.0.10 < 16.0.10
security-reporting < 17.0.5 < 17.0.5
