Remote Command Execution Vulnerability in FreePBX Text-To-Speech Module
CVE-2026-73660

7.5HIGH

Key Information:

Vendor

Freepbx

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73660?

The Text-To-Speech module in FreePBX, versions prior to 16.0.6 and 17.0.5.4, contains a vulnerability that permits authenticated administrators to exploit HTML-encoded TTS destination names. This flaw allows the names to be decoded during the dialplan generation process, eventually leading to arbitrary command execution as the asterisk service user. The vulnerability emphasizes the importance of updating to the latest versions to mitigate risks associated with command execution in the AGI context. Users are strongly advised to apply the necessary updates as detailed in the official advisories.

Affected Version(s)

tts < 16.0.6 < 16.0.6

tts >= 17.0.1, < 17.0.5.4 < 17.0.1, 17.0.5.4

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.