Authentication Bypass in FreePBX Framework Module
CVE-2026-73661

8.6HIGH

Key Information:

Vendor

Freepbx

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73661?

The FreePBX Framework module allows an authenticated user with backup-restore and write access to backup files to circumvent authentication mechanisms. Through a crafted backup restoration process, the hidden AUTHTYPE setting can be restored with a value of 'none', effectively disabling authentication. This vulnerability poses significant security risks, enabling unauthorized access during the restoration phase. The issue has been rectified in versions 16.0.47 and 17.0.30.

Affected Version(s)

framework < 16.0.47 < 16.0.47

framework >= 17.0.1, < 17.0.30 < 17.0.1, 17.0.30

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.