Arbitrary Command Execution Vulnerability in FreePBX by Sangoma
CVE-2026-75600
8.6HIGH
What is CVE-2026-75600?
FreePBX, an open-source IP PBX, has a vulnerability that allows authenticated users with access to the GraphQL API module to execute arbitrary shell commands. This is due to insufficient validation of user-provided parameters when constructing shell command executions. Although the generated OAuth access token is validated, the user-defined host parameter is not properly validated or escaped, posing a significant risk of unauthorized command execution as the FreePBX service user, typically 'asterisk'. This vulnerability has been addressed in version 17.0.9.
Affected Version(s)
security-reporting < 17.0.9
