CVE-2026-73664

8.6

FreePBX · backup

The FreePBX backup module contains an access control vulnerability that allows authenticated users with high privileges to perform unauthorized actions due to improper privilege management.

Executive summary

An access control flaw in the FreePBX backup module permits high-privileged users to bypass restrictions, potentially leading to full system compromise.

Vulnerability

The vulnerability stems from improper privilege management (CWE-269) and incorrect permission assignment for critical resources (CWE-732). An attacker must already possess high privileges to exploit this, indicating that this is an escalation of authority issue.

Business impact

Exploitation of this vulnerability could allow an attacker to manipulate system backups, gain unauthorized access to sensitive configuration files, or disrupt PBX services. With a CVSS score of 8.6, this represents a major risk to the availability and security of telecommunications infrastructure.

Remediation

Immediate Action: Update the FreePBX backup module to version 17.0.11 or later as soon as it becomes available from the vendor.

Proactive Monitoring: Audit administrative user accounts and review logs for unauthorized configuration changes or unexpected access to backup directory resources.

Compensating Controls: Restrict administrative access to the FreePBX management interface to known, trusted IP addresses using firewall rules.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

While this requires authenticated access, the potential for high-level system impact necessitates a swift response. Administrators should prioritize the update of the backup module and review current access control policies to minimize the potential for internal threats.

More FreePBX CVEs