Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-75600— FreePBX: Authenticated API generatedocs Host Command Injection

Quick assessment

Affected
FreePBX security-reporting
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

FreePBX 是一款开源的 IP PBX(IP 电话系统)软件。在 17.0.9 版本之前,经过身份验证并被授权访问 FreePBX 的 GraphQL API 模块接口的用户,可以执行任意 Shell 命令。要利用此漏洞,必须首先通过 API 模块的身份验证。 该漏洞源于 PBX API 模块中的文档生成器接受一个经过身份验证的主机(host)参数,并将其直接用于构建 Shell 命令。虽然代码路径在执行前会验证生成的 OAuth 访问令牌,但并未对主机参数进行验证或转义处理。这导致攻击者在通过身份验证后,可以

CVSS 8.6 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
FreePBX security-reporting < 17.0.9 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75600

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FreePBX: Authenticated API generatedocs Host Command Injection
Source: CVE Program / CVE List V5
Vulnerability Description
FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL api module interface of FreePBX are able to execute arbitrary shell commands. Authenticated access to the api module is required. The PBX API module's documentation generator accepts an authenticated host parameter and uses it to build a shell command. The code path validates the generated OAuth access token before execution, but it does not validate or escape host. Compromise results in authenticated arbitrary shell command execution as the FreePBX web/PBX service user (typically asterisk.). This issue has been patched in version 17.0.9.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
FreePBX security-reporting < 17.0.9 -

II. Public POCs for CVE-2026-75600

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75600

请登录查看更多情报信息。

Other References for CVE-2026-75600 (1)

Same Patch Batch · FreePBX · 2026-09-28 · 6 CVEs total

CVE-2026-54675 8.7 HIGH FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Modu
CVE-2026-54710 8.6 HIGH FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclus
CVE-2026-54708 8.6 HIGH Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module
CVE-2026-54674 8.6 HIGH Authenticated Command Injection in FreePBX UCP Interface
CVE-2026-45562 7.7 HIGH FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module

IV. Related Vulnerabilities

V. Comments for CVE-2026-75600

No comments yet


Leave a comment