CVE-2026-28284: FreePBX: Authenticated SQL Injection Vulnerabilities in FreePBX Logfiles Module
Published Mar 5, 2026
·Updated
FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. This issue has been patched in versions 16.0.10 and 17.0.5.
Affected Software
3 affected components
FreePBX FreePBX<16.0.10, <17.0.5
Sangoma FreePBX>=16.0<16.0.10
Sangoma FreePBX>=17.0<17.0.5
Event History
Mar 5, 2026
CVE Published
via MITRE·06:24 PM
Data Sourced
via MITRE·06:24 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-28284?
CVE-2026-28284 is classified as a high-severity vulnerability due to its potential for authenticated SQL injection attacks.
2
How do I fix CVE-2026-28284?
To address CVE-2026-28284, upgrade FreePBX to version 16.0.10 or 17.0.5 or higher.
3
Who is affected by CVE-2026-28284?
CVE-2026-28284 affects users of FreePBX versions prior to 16.0.10 and 17.0.5.
4
What are the potential impacts of CVE-2026-28284?
Exploitation of CVE-2026-28284 may allow attackers to execute arbitrary SQL commands, compromising the database.
5
Is CVE-2026-28284 still an issue in the latest FreePBX versions?
No, CVE-2026-28284 has been patched in the latest versions 16.0.10 and 17.0.5 of FreePBX.