CVE-2026-28287
8.8FreePBX · FreePBX
FreePBX contains multiple OS command injection vulnerabilities in the recordings module that allow authenticated administrative users to execute arbitrary system commands.
Executive summary
The FreePBX IP PBX software is vulnerable to OS command injection, which could allow an authenticated administrator to achieve full system compromise.
Vulnerability
This flaw is an OS command injection (CWE-78) located within the recordings module of the application. It requires an attacker to have administrative privileges to successfully trigger the injection.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary OS commands on the underlying host, potentially leading to a complete compromise of the PBX system. Given the CVSS score of 8.8, this represents a high-severity risk that could result in unauthorized data access, disruption of critical telephony services, and potential lateral movement within the network.
Remediation
Immediate Action: Update the FreePBX recordings module to version 16.0.20 or 17.0.5 immediately to apply the vendor-supplied security patches.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected command-line activity originating from the web server user account.
Compensating Controls: Restrict administrative access to the FreePBX management interface to known, trusted IP addresses and implement strict network segmentation to limit the impact of a potential breach.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this command injection flaw, combined with the criticality of telephony infrastructure, necessitates prompt action. Administrators should verify their current version of the recordings module and apply the necessary updates to reach the secure versions. Failure to patch leaves the system exposed to potential full-system compromise by any user with administrative access.