SQL Injection Vulnerability in FreePBX Missed Call Module
CVE-2026-73663

9.3CRITICAL

Key Information:

Vendor

Freepbx

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73663?

The missedcall module in FreePBX versions 16.0.0 through 16.0.11 and 17.0.4 is susceptible to SQL injection due to improper handling of inbound Caller ID names from crafted SIP From headers. This vulnerability allows an unauthenticated caller to inject malicious SQL code during missed calls, which can result in database corruption and unauthorized alterations to administrator accounts. This security flaw has been rectified in FreePBX versions 16.0.11 and 17.0.4.

Affected Version(s)

missedcall < 16.0.11 < 16.0.11

missedcall >= 17.0.1, < 17.0.4 < 17.0.1, 17.0.4

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.