Authentication Bypass in FreePBX UCP Node Server
CVE-2026-73665

9.3CRITICAL

Key Information:

Vendor

Freepbx

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73665?

A vulnerability exists in FreePBX that allows an unauthenticated client to access custom namespaces on the UCP Node server. The issue arises from the way Socket.IO handles middleware for authentication, which leads to the potential for arbitrary command execution when specific crafted event values are sent through the Asterisk Manager Interface. This flaw has been addressed in version 17.0.9, making it critical for users to upgrade to maintain security.

Affected Version(s)

ucp < 17.0.9

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.