Remote Code Execution Vulnerability in FreePBX Superfecta Module
CVE-2026-54710

8.6HIGH

Key Information:

Vendor

Freepbx

Vendor
CVE Published:
28 September 2026

What is CVE-2026-54710?

The FreePBX Superfecta module is susceptible to a remote code execution vulnerability due to unsafe inclusion of PHP files. This issue, present in versions before 16.0.40 and 17.0.7, allows authenticated attackers with a known username to execute arbitrary PHP code on the server by exploiting user-supplied input within the module's AJAX handler. By manipulating the inclusion of PHP files from the sources/ directory, attackers can gain control over the server's functionalities. This vulnerability is particularly dangerous when combined with features such as backup module's arbitrary directory creation and soundlang module's file uploads that disclose full paths, ultimately placing server integrity at significant risk.

Affected Version(s)

security-reporting < 16.0.40 < 16.0.40

security-reporting < 17.0.7 < 17.0.7

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.