Remote Command Execution Vulnerability in FreePBX Text-To-Speech Module
CVE-2026-73660
7.5HIGH
What is CVE-2026-73660?
The Text-To-Speech module in FreePBX, versions prior to 16.0.6 and 17.0.5.4, contains a vulnerability that permits authenticated administrators to exploit HTML-encoded TTS destination names. This flaw allows the names to be decoded during the dialplan generation process, eventually leading to arbitrary command execution as the asterisk service user. The vulnerability emphasizes the importance of updating to the latest versions to mitigate risks associated with command execution in the AGI context. Users are strongly advised to apply the necessary updates as detailed in the official advisories.
Affected Version(s)
tts < 16.0.6 < 16.0.6
tts >= 17.0.1, < 17.0.5.4 < 17.0.1, 17.0.5.4
