CVE-2026-28210: FreePBX: Authenticated SQL Injection in CDR (Call Data Record) Reports
Published Mar 5, 2026
·Updated
FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnerable to SQL query injection. This issue has been patched in versions 16.0.49 and 17.0.7.
Affected Software
3 affected components
FreePBX FreePBX<16.0.49, <17.0.7
Sangoma FreePBX>=16.0<16.0.49
Sangoma FreePBX>=17.0<17.0.7
Event History
Mar 5, 2026
CVE Published
via MITRE·06:24 PM
Data Sourced
via MITRE·06:24 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Sep 13, 58150
Event
via FIRST·01:12 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-28210?
CVE-2026-28210 is classified as a medium severity vulnerability due to the potential for authenticated SQL injection.
2
How do I fix CVE-2026-28210?
To fix CVE-2026-28210, upgrade to FreePBX versions 16.0.49 or 17.0.7 or later.
3
What versions of FreePBX are affected by CVE-2026-28210?
FreePBX versions prior to 16.0.49 and 17.0.7 are affected by CVE-2026-28210.
4
What type of vulnerability is CVE-2026-28210?
CVE-2026-28210 is an authenticated SQL injection vulnerability in the CDR reports of FreePBX.
5
Is CVE-2026-28210 present in FreePBX installations?
CVE-2026-28210 is present in all FreePBX installations that have not been updated to the patched versions.