Remote Code Execution Vulnerability in FreePBX Superfecta Module
CVE-2026-54710
What is CVE-2026-54710?
The FreePBX Superfecta module is susceptible to a remote code execution vulnerability due to unsafe inclusion of PHP files. This issue, present in versions before 16.0.40 and 17.0.7, allows authenticated attackers with a known username to execute arbitrary PHP code on the server by exploiting user-supplied input within the module's AJAX handler. By manipulating the inclusion of PHP files from the sources/ directory, attackers can gain control over the server's functionalities. This vulnerability is particularly dangerous when combined with features such as backup module's arbitrary directory creation and soundlang module's file uploads that disclose full paths, ultimately placing server integrity at significant risk.
Affected Version(s)
security-reporting < 16.0.40 < 16.0.40
security-reporting < 17.0.7 < 17.0.7
