Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-54710— FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclusion)

Quick assessment

Affected
FreePBX security-reporting
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

FreePBX 是一款开源 IP 电话交换系统(IP PBX)。在 16.0.40 和 17.0.7 版本之前,其 superfecta 模块中存在一个关键远程代码执行(RCE)漏洞,该漏洞源于对任意 PHP 文件的不安全包含。攻击者只要拥有合法的认证凭据,即可利用此漏洞以 Web 服务器用户的权限在服务器上执行任意 PHP 代码。漏洞利用需要已知用户名的认证。 该漏洞的根本原因在于 Superfecta 模块的 AJAX 处理程序中“options”和“save_options”处理逻辑。相关代码会根据用户提供的

CVSS 8.6 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 2

VendorProduct Version RangeStatus
FreePBX security-reporting < 16.0.40 affected
< 17.0.7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54710

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclusion)
Source: CVE Program / CVE List V5
Vulnerability Description
FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerability exists in the superfecta module due to unsafe inclusion of arbitrary PHP files, allowing authenticated attackers to execute arbitrary PHP code on the server with the privileges of the web server user. Authentication with a known username is required. The vulnerability is rooted in the options and save_options cases in the Superfecta module's AJAX handler. The code dynamically includes PHP files from the sources/ directory based on user-supplied input. This allows an attacker to execute arbitrary code when combined with arbitrary directory creation (e.g., via the backup module) and file uploads that reveal full paths (e.g., via the soundlang module). This issue has been patched in versions 16.0.40 and 17.0.7.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
FreePBX security-reporting < 16.0.40 -

II. Public POCs for CVE-2026-54710

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54710

请登录查看更多情报信息。

Other References for CVE-2026-54710 (1)

Same Patch Batch · FreePBX · 2026-09-28 · 6 CVEs total

CVE-2026-54675 8.7 HIGH FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Modu
CVE-2026-75600 8.6 HIGH FreePBX: Authenticated API generatedocs Host Command Injection
CVE-2026-54708 8.6 HIGH Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module
CVE-2026-54674 8.6 HIGH Authenticated Command Injection in FreePBX UCP Interface
CVE-2026-45562 7.7 HIGH FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module

IV. Related Vulnerabilities

V. Comments for CVE-2026-54710

No comments yet


Leave a comment