Authentication Bypass in FreePBX UCP Node Server
CVE-2026-73665
9.3CRITICAL
What is CVE-2026-73665?
A vulnerability exists in FreePBX that allows an unauthenticated client to access custom namespaces on the UCP Node server. The issue arises from the way Socket.IO handles middleware for authentication, which leads to the potential for arbitrary command execution when specific crafted event values are sent through the Asterisk Manager Interface. This flaw has been addressed in version 17.0.9, making it critical for users to upgrade to maintain security.
Affected Version(s)
ucp < 17.0.9
