SQL Injection Vulnerability in FreePBX Missed Call Module
CVE-2026-73663
9.3CRITICAL
What is CVE-2026-73663?
The missedcall module in FreePBX versions 16.0.0 through 16.0.11 and 17.0.4 is susceptible to SQL injection due to improper handling of inbound Caller ID names from crafted SIP From headers. This vulnerability allows an unauthenticated caller to inject malicious SQL code during missed calls, which can result in database corruption and unauthorized alterations to administrator accounts. This security flaw has been rectified in FreePBX versions 16.0.11 and 17.0.4.
Affected Version(s)
missedcall < 16.0.11 < 16.0.11
missedcall >= 17.0.1, < 17.0.4 < 17.0.1, 17.0.4
