CVE-2026-28209: FreePBX: Command Injection leading to Remote Code Execution in FreePBX ElevenLabs Text-to-Speech integration
FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, a command injection vulnerability exists in FreePBX when using the ElevenLabs Text-to-Speech (TTS) engine in the recordings module. This issue has been patched in versions 16.0.20 and 17.0.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28209?
CVE-2026-28209 is considered to be a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-28209?
To fix CVE-2026-28209, you should upgrade FreePBX to version 16.0.20 or 17.0.5 or later.
Which FreePBX versions are affected by CVE-2026-28209?
CVE-2026-28209 affects FreePBX versions 16.0.17.2 through 16.0.19 and 17.0.2.4 through 17.0.4.
What type of vulnerability is CVE-2026-28209?
CVE-2026-28209 is a command injection vulnerability that can lead to remote code execution.
Is there a workaround for CVE-2026-28209?
There is no recommended workaround for CVE-2026-28209; upgrading to a secure version is the primary mitigation method.